A missing security policy and very little visible community support reduce transparency. The project is not archived and has a substantial release history, but future fixes remain uncertain.
54%
Total Score
50
75
50
The manifest declares MIT, while bundled license files identify MPL-1.1, GPL-2.0, and LGPL-2.1 components; this may be normal for included third-party assets but leaves licensing scope unclear.
The package has 156 releases over more than 10 years and a release within the last year, but only one release in the last 12 months indicates a markedly slower current cadence.
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance warning even though a release was published within the last year.
The linked repository has zero stars, forks, and watchers, providing no visible community support or adoption signal to offset the thin maintenance evidence.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
dot/auth Version * | — | — |
dot/media Version * | — | — |
dot/roles Version * | — | — |
dot/users Version * | — | — |
dot/options Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.