The repository has no tests or security policy, and community activity is minimal. The MIT license, stable version, and lack of install scripts improve transparency and reduce installation risk but do not offset the maintenance concerns.
42%
Total Score
0
71
75
Only three releases exist, with the latest published in July 2021 and none in the last five years. This strongly raises abandonment risk, although the package is not deprecated.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and indicating no current maintenance capacity.
The package includes a very short eight-character README and the repository has no tests or changelog. Missing tests and changelogs are common for published artifacts, but the minimal consumer documentation is a modest usability concern.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of community support.
No security policy was found in the repository, leaving users without a documented vulnerability-reporting path. This is a transparency gap, though it is less significant than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.2 | — | — |
codememory/fs Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.