The package has a clear GPL-2.0+ declaration and no install-time scripts, but its documentation is only a short name heading. The source repository lacks a security policy and does not identify the package in its README, making long-term support harder to verify.
38%
Total Score
33
100
67
83
This is the package's only release, published in August 2014, with no releases in the last 12 months. The long period without a new release is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has seen no meaningful maintenance for many years.
The repository owner is a user account rather than an organization, and the provided data does not show organizational backing. This offers no compensating support evidence but is not a severe risk by itself.
There was no recent issue or pull-request activity. Combined with the old last push, this provides no evidence of an active support channel.
The repository name does not match the package name and its README does not mention the package. Although this can occur with subpackages, here it makes the repository-package relationship harder to verify.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.