It includes a substantial README, tests, changelog, MIT licensing, and a repository that clearly matches the package. There is no security policy and only one registry maintainer, leaving future support dependent on a narrow base.
60%
Total Score
25
100
83
75
The latest release was about 4 years ago, with no releases in the last 12 months, despite 15 releases overall. This indicates meaningful abandonment risk for a dependency that may need compatibility updates.
The repository had zero commits and zero active maintainers in the last 3 months. The lack of recent development reinforces the stale release history and lowers confidence in ongoing maintenance.
Only one account has registry publish access. Because the repository is user-owned rather than organization-backed, this represents a narrow publishing and support base.
The repository has no security policy. This is a transparency and response-process gap, although it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version 2.* | — | — |
npm-asset/jsoneditor Version >=5.0 <10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.