The repository has no commits or active maintainers in the last three months, and security scanning is not configured. Long release history, a current stable release, repository tests, release notes, and a matching source repository provide useful confidence.
72%
Total Score
50
50
86
75
Seven runtime dependencies, including the framework and several companion addons, create a relatively broad dependency surface that can increase upgrade and maintenance burden.
Only one registry account has publish access. The matching user-owned repository provides some continuity, but the narrow publisher base leaves limited redundancy if that maintainer becomes unavailable.
The registry namespace and repository owner are the same individual account. This confirms ownership continuity but does not provide organizational backing or a broader maintenance base.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the package had a recent release and is not archived.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide little external validation or visible community depth.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bearframework/bearframework Version 1.* | — | — |
bearframework/localization-addon Version 1.* | — | — |
ivopetkov/js-lightbox-bearframework-addon Version 1.* | — | — |
ivopetkov/client-packages-bearframework-addon Version 1.* | — | — |
ivopetkov/server-requests-bearframework-addon Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.