The package has had no release or commit activity for nearly six years, and its repository does not identify the package in its name or README. The MIT declaration, readable package contents, and lack of deprecation provide limited reassurance, but maintenance and ownership transparency remain weak.
42%
Total Score
50
72
75
The package has only two releases, both published on the same day in September 2020, with no releases in the past six years. This is strong evidence of abandonment risk for a package handling application form and database functionality.
Only one registry account has publishing access. A single maintainer is not inherently unhealthy, but no provided project-backing signal shows a broader organization or team to compensate for that dependency.
The repository is owned by an individual account rather than an organization, and no organizational backing is shown. Combined with one registry maintainer, this leaves limited visible continuity if the maintainer stops work.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the nearly six-year gap since the last release. No newer activity is provided to offset the maintenance concern.
The linked repository name does not match the package name, and its README does not mention the package. That weakens confidence that the repository clearly represents this release, although a subpackage or naming difference could explain it.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.