The small, readable artifact has a clear license, minimal install behavior, and no workflow exposure. Its maintenance record is stale, with no commits or releases for over four years, while security scanning and a security policy are absent.
45%
Total Score
33
100
63
83
The package has six releases, but all were clustered in roughly 12 days and none were published in the last four years. This strongly indicates abandonment risk despite the initial release activity.
There were zero commits and zero active maintainers in the last three months, consistent with the multi-year release gap. This is a substantial abandonment concern for a package used in development tooling.
The package and repository are owned by an individual rather than an organization. That is ordinary for a small open-source project, but it provides limited visible backing when maintenance activity has stopped.
There were no new or closed issues or pull requests in the last month. With no recent commits or releases, this reinforces the picture of an inactive project rather than demonstrating healthy issue resolution.
The repository has zero stars and forks and one watcher, providing little evidence of broad community validation. Popularity is only supporting evidence, so this is a minor concern rather than a decisive risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
drupal/coder Version ^8.3 | — | — |
moodlehq/moodle-cs Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.