The stable 1.0.1 release and lack of registry deprecation are positives, but its small two-release history provides little evidence of ongoing support. Seven runtime dependencies add maintenance surface, while the project has no security policy or automated security scanning.
35%
Total Score
0
50
64
88
Only two releases exist, and the latest was published in May 2017; there have been no releases in more than nine years. This is strong evidence of abandonment risk despite the stable version.
There were no commits and no active maintainers in the last three months, consistent with the release history showing long-term inactivity.
Seven runtime dependencies create a meaningful maintenance and transitive-risk surface for an otherwise small package. No development dependencies are declared, which offers little evidence of a maintained test or release workflow.
No declared license, recognized license text, or license file was found in the package or repository. That leaves legal reuse terms unclear.
Composer is used for builds, but no security-scanning tooling is configured. This is a transparency and maintenance weakness rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
infrajs/load Version ~1 | — | — |
infrajs/excel Version ~1 | — | — |
akiyatkin/goal Version ~1 | — | — |
narical/grayscale Version ~1 | — | — |
infrajs/layer-config Version ~1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.