The author should describe this more clearly, without jargon or the word threat which seems an odd choice in this case. I had to read the whole readme to figure out it does length and depth validation on a json payload. Hopefully it handles streaming data.