The MIT license, clear README, release notes, and source tests support transparent maintenance. Its small dependency set and lack of install-time scripts reduce adoption risk.
38%
Total Score
75
100
71
83
Packagist marks the package abandoned at package scope, with no replacement different from the package itself. That is a serious warning for a new dependency despite the maintained-looking source repository.
The package has existed for over 10 years with 15 releases, but it has had no release in the last 12 months and its latest release was over two years ago. This points to stalled registry maintenance.
The repository recorded no commits and no active maintainers in the last three months. That weakens the evidence of ongoing maintenance, although the repository is not archived.
The linked repository name does not match the package name and its README does not mention the package. This creates some uncertainty that the repository is the authoritative source, even though the repository structure otherwise resembles the package.
The repository has no security policy. This is a transparency gap, though it is less significant than the package-level abandonment and release-history concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^3.2 || ^2.7.0 || ^1.2.1 | — | — |
react/event-loop Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.