A library for promises (CommonJS/Promises/A,B,D)
10%
Total Score
25
100
56
50
The entire package is deprecated, with the publisher recommending migration to native JavaScript promises and offering no replacement package. This is a severe adoption and support risk.
The package has 76 releases and a long history, but its latest release was in October 2017 and it had no releases in the last 12 months. That indicates prolonged release inactivity.
The repository had zero commits and zero active maintainers in the last three months, consistent with the package's inactive and archived state.
The linked repository is archived, so it is no longer an actively maintained project even though it was pushed in November 2023. Archived status strongly raises abandonment risk.
A prepublish lifecycle script is present. This is worth noting because publishing behavior is less minimal, but the signal alone does not establish a serious dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.