Recent releases, stable versioning, and a small dependency surface are positive. Documentation is substantial, but the project provides no security policy and limited evidence of broader review or continuity.
45%
Total Score
50
100
80
50
The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. That creates a serious distribution and usage constraint for an open-source dependency.
One contributor made all two recent commits, leaving maintenance dependent on a single individual without evidence of a broader active contributor base.
Only two commits were recorded in the last three months, indicating limited recent maintenance activity despite the recent release history.
The repository has no security policy. For a framework handling routing, cookies, uploads, authentication, and database access, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.