Risky to adopt: the release has had no updates for more than four years and the project has only two releases. It has a usable README and is backed by an organization, but the missing license and security policy leave important maintenance and transparency gaps.
42%
Total Score
50
100
70
75
The package has only two releases, both published on November 9, 2021, with no releases in the last 12 months. This indicates a long-standing, effectively stagnant release history for a package that integrates an external API.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with its last push occurring more than four years ago. The organization backing does not compensate for the absence of observed maintenance activity.
Neither a declared license nor a license file was found in the package or repository. This creates a significant legal and transparency concern for adopting the dependency.
The repository has no security policy. While this is not proof of a security problem, it reduces transparency about how vulnerabilities are reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos Version * | — | — |
tinify/tinify Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.