The license, package contents, and install behavior are clear, with organization backing and a matching README reference. Maintenance appears stalled, and the README says development is moving to another repository, so pinning this release carries a meaningful continuity risk.
55%
Total Score
100
79
75
The artifact includes a readable README, which supports consumer use; missing tests and a changelog are normal for a published package and are not gaps here. However, the README explicitly says the repository is being rewritten elsewhere, creating continuity risk for this release.
The package has had no release in over two years and no releases in the last 12 months, despite five releases arriving within about 10 days in February 2024. This is a substantial maintenance concern, though the repository is not archived and the package is not deprecated.
The repository is not archived, which is a positive sign, but it was last pushed over two years ago. That stale repository state reinforces the release-history concern without showing definitive abandonment.
The linked repository has no security policy. This is a transparency and maintenance gap, although it is less significant than the stale release and repository activity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dizatech/burp Version ^3.1.0 | — | — |
intervention/image Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.