The package includes tests, a README, and an MIT license, with no install-time scripts. Its eight runtime dependencies and single-maintainer publishing setup add upkeep burden.
35%
Total Score
33
50
63
83
This is the package's only release, published about 10 years ago, with no releases in the last 12 months. That strongly increases abandonment risk despite the repository remaining available.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive since 2016. This is the primary reason adoption carries abandonment risk.
Eight runtime dependencies create meaningful compatibility and maintenance surface for a small, long-inactive package. The signal does not show that any dependency is unsafe, so this is a maintenance caution rather than a severe risk.
Only one registry account has publish access. That is a limited publishing base, and the repository's user-owned backing provides no demonstrated organizational maintenance capacity.
The repository is user-owned rather than organization-owned, and no organizational backing is shown. Combined with the inactivity evidence, this offers little assurance of continued maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
easy-system/es-mvc Version * | — | — |
easy-system/es-http Version * | — | — |
easy-system/es-events Version * | — | — |
easy-system/es-system Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.