The package includes a usable README, an MIT declaration, and a small dependency set. It has no tests or security scanning, which leaves maintenance and integration risks for a file-upload library.
35%
Total Score
25
100
72
83
The latest release was in September 2018, with no releases in the last 12 months; roughly eight years without a release is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months, consistent with the release history and indicating that fixes are unlikely to arrive promptly.
The repository owner is an individual user rather than an organization, so there is no provided evidence of broader project backing to compensate for the inactive maintainer base.
The repository has zero stars, forks, and watchers. This is weak supporting evidence rather than a verdict, but it provides no community signal to offset the inactivity.
Composer is used for builds, but no security scanning tools are configured, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
jsnlib/rand Version >=1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.