Risky to adopt for a security-sensitive session package: it has had no release or repository activity since March 2017. The small, simple dependency profile and clear README help, but the long abandonment period and lack of a security policy leave maintenance concerns unresolved.
42%
Total Score
33
100
67
90
The latest release was over 9 years ago, with no releases in the last 12 months; this is a substantial abandonment risk for a session-handling library.
There were zero commits and zero active maintainers in the last 3 months, consistent with a project that has been inactive for years.
The repository is not marked archived, but it was last pushed over 9 years ago; the stale repository state still supports the maintenance concern shown by release history.
The registry namespace and repository owner match, and the owner is an individual rather than an organization; this supports ownership alignment but provides limited maintainer capacity.
There are no open issues or pull requests and no recent activity; while this avoids an unresolved backlog, it does not demonstrate ongoing maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.