A single maintainer and the missing source link reduce confidence in ongoing support. The package is well established and its artifact includes a README, while installation scripts add no extra risk. The repository could not be found, so maintenance and provenance remain unverified.
62%
Total Score
50
50
90
100
Seven runtime dependencies are declared, all within the same ACP3 ecosystem, with no development dependencies; this is a focused but coupling-heavy dependency profile.
Only one registry maintainer is listed, leaving limited visible publishing capacity and increasing continuity risk if that maintainer becomes inactive.
The package has 353 releases and has existed for over 10 years, but it has had no releases in the last 14 months, indicating slowed maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
acp3/core Version 4.0.0-rc.29.3 | — | — |
acp3/setup Version 4.0.0-rc.29.3 | — | — |
acp3/module-users Version 4.0.0-rc.29.3 | — | — |
acp3/module-errors Version 4.0.0-rc.29.3 | — | — |
acp3/module-system Version 4.0.0-rc.29.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.