The license metadata conflicts with the MIT license file, and the package contains no README. Its small dependency surface and lack of install scripts reduce operational risk, but maintenance cannot be verified.
42%
Total Score
100
60
75
The latest release was in June 2018, about 8 years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
The manifest declares a proprietary license, while the included LICENSE file is recognized as MIT. The license file is compensating evidence, but the mismatch creates legal ambiguity.
The artifact contains only three files—LICENSE, Mongo.hh, and composer.json—indicating a very thin package. That may fit a small header-only driver, but it provides little consumer documentation or provenance evidence.
The artifact has no README, which makes a library harder to integrate. The absence of tests and a changelog is normal for a published artifact and is not treated as a gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intaglio/nuclio-core Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.