The project has stopped showing activity after a brief launch period, and it has no security policy. Tests, a useful README, and a clear MIT license provide reasonable transparency for a small library.
61%
Total Score
50
100
83
75
The source repository is owned by an individual account rather than an organization, so the package appears to rely on a single-person project rather than broader organizational backing.
The package has three releases, all published within roughly one day, with no later release during its roughly nine-month history after that burst. This suggests limited demonstrated maintenance, though the project is still relatively young.
There were no commits and no active maintainers in the last three months. Combined with the older last push, this is meaningful evidence that maintenance may have stalled.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for a young, small package, not a severe concern by itself.
The repository uses Composer build tooling, but no security scanning tools were detected. The missing security automation is a modest hygiene concern for a dependency project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
losthost/db Version ~3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.