The package is clearly licensed, has a matching three-file repository, and avoids install scripts. Its single release and no maintenance activity for 9 years leave a security-related plugin with little evidence of ongoing support.
39%
Total Score
25
75
75
This release is the package's only release, published 9 years ago, with no releases in the last 12 months. That strongly suggests abandonment despite the package's small scope.
The repository has recorded no commits and no active maintainers in the last 3 months, consistent with the 9-year release gap and indicating no current maintenance capacity.
Only one registry account can publish the package, which is a thin publishing base. Organization ownership provides some backing, but the repository's inactivity does not show active support.
The linked repository has no security policy. For a plugin intended to protect publicly accessible sites, this reduces transparency around vulnerability reporting and support.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.