Tests, a short README, and an MIT declaration provide basic consumer and licensing transparency. The lack of a security policy and minimal repository adoption add maintenance uncertainty.
32%
Total Score
0
58
50
Only two releases were published, both in December 2014, with no release in nearly 12 years. This is strong evidence of abandonment despite the package not being registry-deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was in December 2014. The long collapse in activity materially increases maintenance and compatibility risk.
The repository name matches the package, but its README does not mention the package name. The match reduces concern, while the missing README reference leaves a minor provenance and documentation gap.
The repository has zero stars and forks and only one watcher. Popularity is not decisive by itself, but these counters provide little supporting evidence of active community use.
The linked repository has no security policy. For an authentication-related bundle, that is a meaningful transparency and vulnerability-reporting gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opine/cache Version ~2.0 | — | — |
opine/route Version ~3.0 | — | — |
opine/config Version ~3.0 | — | — |
opine/person Version ~2.0 | — | — |
opine/pubsub Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.