The package is small and clearly licensed, with no install-time scripts or workflow findings. The linked repository does not identify this package in its README, which weakens transparency.
32%
Total Score
100
50
75
The last release was in September 2015, with no releases in the past 12 months and only four releases overall. This is strong evidence of abandonment risk for a dependency.
The repository is not archived, but it was last pushed in December 2015, providing no evidence of active maintenance for more than 10 years.
The repository name does not match the package name and its README does not mention the package, weakening confidence that it is the package's intended source repository.
The repository has no security policy. For a small, inactive package this adds a transparency gap, though it is less significant than the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
exsyst/io Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.