Its README, tests, and changelog make the small codebase transparent. There is no repository security policy, and the single maintainer leaves limited continuity.
58%
Total Score
50
88
75
Only one registry publishing maintainer is listed, which limits continuity if that person stops maintaining the package. The repository and package are coherent, but no broader maintainer base is shown.
This package has one release, published about four years ago, with no releases in the last 12 months. That is strong evidence of stagnant maintenance, although the small, complete package may require few changes.
The linked repository has no security policy. This weakens vulnerability-reporting transparency, though the package is small and otherwise includes tests and documentation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lum/lum-data Version ^1.0 | — | — |
lum/lum-arrays Version ^2.0 | — | — |
lum/lum-compat Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.