Its six runtime dependencies and small development footprint add integration risk, while the registry does not mark it deprecated. The repository could not be found, limiting verification of maintenance and provenance.
35%
Total Score
50
50
50
The package has had no release in more than six years, with zero releases in the last 12 months. This is strong evidence of abandonment risk despite its earlier ten-release history.
Six runtime dependencies increase integration and maintenance exposure, although the dependency list is concrete and aligned with the package's installer-module purpose.
One registry maintainer indicates a thin publishing base and limited visible continuity if that person becomes unavailable. This is a meaningful resilience concern, but registry access alone does not prove active maintenance.
Version 0.3.1 is not a stable major release, so compatibility and maturity are less established. The absence of recent prereleases does not offset the long period without releases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
knot-lib/di Version ~0.1 | — | — |
knot-lib/kernel Version ~0.1 | — | — |
knot-lib/module Version ~0.1 | — | — |
knot-lib/services Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.