The package has no release activity since its sole release in 2020, and the repository README describes a different package. It has a clear MIT declaration and a usable README, but the long inactivity makes adoption a liability.
38%
Total Score
100
61
50
This is the only release, published about six years ago, with no releases in the last 12 months. That strongly indicates the package is no longer actively maintained.
Although the repository name matches the package, its README does not mention this package and instead documents a different package. That raises a meaningful concern that the artifact may be associated with the wrong source repository.
The repository has zero stars and forks and one watcher. Popularity is not decisive, but this provides no supporting evidence of broad use or community resilience.
Composer is used for builds, which fits the package ecosystem, but no security scanning tools are present. This is a modest transparency and maintenance gap rather than a severe risk.
The repository is not archived, but it was last pushed about six years ago, consistent with the release history and indicating stale maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codicastudio/permissions Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.