The MIT license, focused dependency set, and matching repository make the package straightforward to inspect and adopt. Release notes and organization backing help, but there is little evidence of ongoing validation.
42%
Total Score
75
100
71
83
The package is reported to borrow the identity of knplabs/knp-snappy, a much more established package, despite zero artifact overlap and no README identification as a fork. Consumers may have intended the lookalike package instead, creating a serious supply-chain adoption risk.
The package has had no release in nearly four years: its latest release was October 2022, with no releases in the last 12 months. The nine-release history shows initial activity but not continued maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. The repository was pushed in February 2024, but that does not demonstrate current maintenance.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap, though not independently disqualifying.
v0.1.0 is not a stable major release, and 44% of recent releases were prereleases. This indicates a less mature compatibility commitment than a stable major version.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.