The README, tests, matching repository, and organizational ownership provide useful support for adoption. The license mismatch and missing security policy reduce transparency, while the release and commit record make long-term maintenance uncertain.
42%
Total Score
50
67
50
The package has 20 releases since May 2018, but none in the last 12 months and its latest recorded release was in September 2020. This long release gap is a substantial maintenance concern.
The repository had zero commits and zero active maintainers in the last three months. That supports the broader evidence of stalled maintenance.
A GPL-3.0 license file is present in both the artifact and repository, but the manifest declares the package proprietary. The conflicting declarations create a meaningful legal and transparency concern.
The repository has no security policy. This is not severe by itself, but it leaves vulnerability reporting and maintenance expectations less clear for a client library.
The assessed version is v3.0.1, while the registry reports v1.1.0 as the latest version; the mismatch makes release metadata and version lineage harder to trust.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fei/api-client Version ^1.1 | — | — |
fei/filer-common Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.