JX's first package
40%
Total Score
0
100
50
75
The package has had only one release, published about 7 years and 10 months ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the lack of releases and providing no evidence of ongoing maintenance.
The package includes a README entry, but it is empty and the project has no tests or changelog. Missing tests and changelog are normal for published artifacts, while the empty consumer documentation is a minor transparency gap.
The repository is not archived, which is a positive status signal, but its last push was about 7 years and 10 months ago and does not offset the inactivity evidence.
The repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This is a hygiene concern for a package intended as a dependency.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.