The MIT license, consumer README, and repository tests make the package straightforward to inspect. A stable release and no deprecation notice are positives, but this is still a poor long-term dependency choice.
40%
Total Score
75
100
67
83
The latest release was about 10 years ago, with only two releases and none in the last 12 months. This is strong evidence of abandonment risk for a dependency.
There were no new issues, closed issues, pull requests, or merges in the last month. With the old last-push date, this supports the conclusion that active maintenance has stopped.
The repository has zero stars and forks and only one watcher. Popularity is not required for health, but these counters provide no supporting evidence of an active user or contributor community.
The repository is not archived, which avoids a severe abandonment signal, but its last push was about 9 years ago. The stale source activity remains a substantial maintenance concern.
The repository has no security policy. This is a transparency gap, though it is secondary to the much stronger evidence of long-term inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tedivm/stash Version v0.13.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.