The declared GPL conflicts with the MIT license detected in the artifact, and the repository has no security policy. Readme, tests, organization backing, and no install-time scripts provide useful safeguards, but do not offset the age and prerelease status.
38%
Total Score
50
67
83
The last release was about 10 years ago, with no releases in the past 12 months; this is strong evidence of abandonment despite three historical releases.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap and indicating little current maintenance capacity.
The package declares GPL, while the artifact license file was detected as MIT. Although license files are present in both the artifact and repository, the mismatch requires clarification before adoption.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package that handles LDAP integration.
Version 2.0.0-rc2 is still a prerelease, and two-thirds of recent releases were prereleases, so consumers lack a clearly finalized stable release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.