The package includes a license, tests, and a repository that matches its name, supporting basic transparency. Its zero-star repository, absent security policy, and nine runtime dependencies add adoption and review concerns.
38%
Total Score
0
50
70
50
Only one release exists, published about 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the release history's long inactivity. The linked repository is not archived, but that does not offset the absent recent activity.
The package declares nine runtime dependencies, including several packages from the same namespace. That increases the maintenance surface and transitive dependency exposure without evidence here that the dependency set is actively maintained.
The repository has 0 stars, 0 forks, and 1 watcher, providing little supporting evidence of community use or review. Popularity is only supporting evidence, so this reinforces rather than determines the maintenance concern.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported. This is a secondary concern because the stronger risk is the prolonged lack of activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
easy-system/es-http Version * | — | — |
easy-system/es-cache Version * | — | — |
easy-system/es-events Version * | — | — |
easy-system/es-router Version * | — | — |
easy-system/es-system Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.