Risky to adopt: the package has had no release or repository activity for about eight years, making abandonment and compatibility issues likely. It is licensed, correctly backed by its matching organization repository, and not deprecated, but those positives do not offset the stalled maintenance.
35%
Total Score
50
71
75
The latest release was published about eight years ago, with no releases in the past 12 months; this is strong evidence that the package is no longer actively maintained.
The repository recorded no commits and no active maintainers during the past three months, reinforcing the long-term maintenance gap rather than compensating for it.
The repository has only 1 star and no forks, providing little community evidence or backup for a package that has otherwise stopped changing.
The repository is not archived, which avoids the strongest abandonment signal, but its last push was also about eight years ago and therefore does not demonstrate current maintenance.
No repository security policy was found. This is a transparency gap, although the absence of workflows and install-time lifecycle scripts limits the associated operational concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mongodb/mongodb Version ^1.3.2 | — | — |
cube-group/myaf-log Version * | — | — |
cube-group/myaf-net Version * | — | — |
cube-group/myaf-utils Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.