It has clear MIT licensing, useful documentation, release notes, and no install-time scripts. The linked repository has no recent activity and does not identify this package in its name or README, so maintenance and ownership are less certain.
55%
Total Score
50
80
75
The latest release was on January 31, 2021, with no releases in the following five years. This is a substantial maintenance concern for a dependency, although the stable 2.0.0 release and small package scope partly reduce the risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. That points to limited ongoing maintenance capacity.
The repository name does not match the package name and its README does not mention the package, weakening confidence that the linked source repository clearly represents this release. A name mismatch can be normal for a sub-package, but no README reference provides no such compensation here.
The linked repository has no security policy. For a small package this is a transparency gap rather than evidence of an active security problem, but it provides little guidance for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
neos/cache Version ^6.1||^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.