The MIT license and lack of install-time scripts are positive, but the package offers no README for consumers. The repository could not be found, leaving maintenance and provenance unverified; pinning this old release is risky.
38%
Total Score
50
50
100
This package has only one release, published over eight years ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
A single registry maintainer provides little visible publishing capacity or redundancy, which increases continuity risk for an already inactive package.
The artifact contains no README, leaving consumers without usage guidance; the absence of tests and a changelog is not a concern because those normally belong in the source repository.
Version 0.1.0 is not a stable major release, so the package offers limited maturity evidence alongside its single-release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/http Version ^0.7 | — | — |
react/socket Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.