The MIT license, clear package contents, and absent install hooks reduce adoption and supply-chain friction. The organization-backed source is not archived, but the registry has not published a release since 2018 and recent repository activity is absent.
62%
Total Score
75
88
83
Only two releases were published, with the latest in 2018 and none in the last 12 months. This is a meaningful maintenance concern, although the linked repository is not archived.
The repository recorded no commits and no active maintainers in the last 3 months, weakening evidence of ongoing maintenance even though the repository is not archived.
The linked repository has no security policy, leaving vulnerability-reporting expectations unspecified. This is a hygiene gap, not evidence that the package is unsafe by itself.
| Title | Versions | Severity |
|---|---|---|
CVE-2018-25050 harvesthq/chosen is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.7. | 0.0.0 - 1.8.7 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.