A small dependency surface and no install-time scripts limit operational exposure. The package still lacks consumer documentation and a security policy, while its long inactivity makes relying on it a liability.
15%
Total Score
0
50
75
No license is declared, and neither the package nor repository contains a license file. This creates a serious adoption and redistribution concern with no compensating licensing evidence.
This is the package's only release, published over 10 years ago, with no releases in the last 12 months. That strongly indicates abandonment rather than an actively maintained dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the last push occurring in 2016 and providing no evidence of current maintenance capacity.
The package has no README, leaving consumers without documented integration guidance. Missing tests and changelog files are not treated as gaps because they belong to source repositories and are not expected in every published artifact.
The repository has no security policy, reducing transparency about vulnerability reporting and support. This is secondary to the much stronger evidence of long-term inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sermepa/sermepa Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.