It has a clear README, tests, MIT licensing, and no install-time scripts. The single-maintainer project has little popularity and no security policy, leaving ongoing support uncertain.
42%
Total Score
50
100
86
75
Only one registry maintainer is listed, and the project backing identifies an individual owner rather than an organization. This leaves limited observable maintainer capacity if support is needed.
The package is over 10 years old but has only three releases, with none in the last 12 months; the latest release was in August 2016. This strongly suggests the project is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with maintenance having stopped after August 2016. This is a substantial abandonment concern.
The repository has zero stars and forks and only one watcher, so there is little visible community activity to provide support or independent scrutiny. Low popularity alone is not disqualifying for a small package.
The linked repository has no security policy and no security-scanning tools. This is a transparency and response-process gap, though it is less important than the long maintenance hiatus.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jstewmc/fx Version ^1.0 | — | — |
jstewmc/interval Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.