The package has a small dependency surface and a matching source repository. Its documentation and project hygiene are limited, so pinning this old release would leave maintenance concerns unresolved.
38%
Total Score
25
100
67
83
This is the package's only release, published about 6 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and materially increasing maintenance risk.
A README is present, but it is only 13 characters and the package and repository report no tests or changelog. The missing tests and changelog are normal packaging practice, while the extremely limited consumer documentation is a minor transparency gap.
The repository is owned by a user account rather than an organization, providing no organization-level backing signal. This is not conclusive, but it leaves the inactive single-maintainer project with limited visible support.
The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no visible community support to offset the inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lsys/config Version ~0.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.