The artifact is small and includes release notes, but its documentation is thin for a library consumers must integrate. The license file says MIT while the manifest declares proprietary, and the repository could not be found, leaving maintenance and provenance unverified.
42%
Total Score
100
60
75
The latest release was in December 2016, with no releases in the last 12 months despite the package being over ten years old. This is strong evidence of abandonment risk.
The artifact contains an MIT license file, but the manifest declares the package proprietary. The mismatch creates uncertainty about the terms consumers can rely on.
The complete artifact contains only four files, including a single header and release notes. This is consistent with a small header-focused package, but provides little visible context for maintenance or integration.
The package has release notes but no README. For a small library, the missing consumer documentation is a genuine usability gap, while the absence of tests in the published artifact is normal packaging practice.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
intaglio/nuclio-core Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.