Its MIT license and matching repository make ownership and reuse clear. The project has had no releases or commits for over five years and lacks security scanning, making maintenance risk substantial.
38%
Total Score
33
50
67
50
The package has only 4 releases, all concentrated in its early period, with no release in over five years. This strongly indicates abandonment risk for a dependency.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the multi-year release gap and materially increasing abandonment risk.
The package declares 7 runtime dependencies, creating meaningful maintenance exposure through its dependency chain, with no provided evidence that this profile is actively managed.
Only one registry account has publish access. That is a limited publishing base, and no organizational backing or active contributor evidence compensates for the concentration.
A README is present and the release has a GitHub release, while the absence of packaged tests and a changelog is normal for published artifacts and is not a health gap here. However, the README is only 5 characters long, offering almost no consumer guidance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codememory/fs Version ^1.1.2 | — | — |
codememory/config Version ^1.1.1 | — | — |
codememory/markup Version 2.0 | — | — |
codememory/caching Version 1.1.1 | — | — |
codememory/support Version 1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.