The package has a clear MIT license, tests, changelog, documentation, organization backing, and security scanning. Confirm that the no-longer-sold product still meets your integration needs before adopting it.
62%
Total Score
63
100
83
50
The package runs pre-install-cmd and pre-update-cmd scripts, adding install-time behavior that consumers must account for. No provided signal shows these scripts are harmful, so this is a hygiene concern rather than a severe risk.
The artifact includes a substantial README, tests, and a changelog, which improve transparency. However, the README states that the underlying product is currently no longer being sold, reducing confidence in future relevance.
The package is mature, first released over 10 years ago, but only one release appeared in the last 12 months. That supports continued publication but suggests a slow maintenance cadence.
All recent commits came from one contributor, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity, which keeps this from being a severe risk.
The repository recorded only one commit in the last three months from one active maintainer. Recent activity exists, but it provides limited evidence of sustained maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tedivm/stash Version ^0.14 | — | — |
guzzlehttp/guzzle Version ^6.2 | — | — |
nannehuiges/jsend Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.