The linked repository does not match the package name, and the manifest declares the package itself as a runtime dependency. MIT licensing and the absence of install-time scripts reduce some risk, but the project shows little evidence of active ownership.
38%
Total Score
0
50
60
100
This package has only one release, published about 7 years ago, with no releases in the last 12 months; that strongly suggests abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and providing no evidence of current maintenance.
The sole declared runtime dependency is the package itself, which is an unusual manifest configuration and may make installation or dependency resolution unreliable.
The artifact contains no README, tests, or changelog, although the package is very small; the missing consumer documentation still reduces transparency for a library dependency.
The linked repository is named “test” rather than matching the package, and no README package mention was found, so its connection to this release is unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hossam20520/comp Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.