The repository is tiny and has one registry maintainer, while its dependency footprint is small and install scripts are absent. Its unarchived status and exact repository match provide limited reassurance, but there is little evidence of ongoing support.
42%
Total Score
0
100
61
75
This release was published in May 2019, and it is the package's only release; there have been no releases in more than seven years. That strongly suggests abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long period without releases. No other maintenance evidence offsets this.
Neither the package nor the linked repository declares or contains a recognized license. Developers therefore lack clear permission to use and redistribute the code.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README is a real usability and transparency gap for a plugin consumers must integrate.
The repository has zero stars and forks and only one watcher, providing no meaningful community support signal. Popularity is supporting evidence, so this reinforces but does not establish the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fed/ewma-module-installer-plugin Version ~0.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.