It has a substantial source tree, tests, documentation, and clear licensing. Transparency is limited by the lack of security tooling and policy, although the repository is not archived and the package is not deprecated.
42%
Total Score
0
71
50
The latest release was in September 2016, with no releases in the last 12 months. This strongly indicates the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with roughly 10 years without visible development. The long inactivity outweighs the package's otherwise mature structure.
The package declares Apache-2.0 and includes recognized license files, so it is licensed. The artifact also contains Zlib-licensed text not covered by the declaration, creating a minor licensing-transparency concern.
The project uses established build tools including make, CMake, and Composer, but no security scanning tools were detected. The build support is positive; the missing scanning is a modest hygiene gap.
The linked repository has no security policy, leaving no documented reporting or response process for vulnerabilities in a package used for RPC and code generation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.