52%
Total Score
caution
Usable with caveats: it is marked proprietary and has had no registry releases in the last 12 months.
The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. This creates a material dependency and redistribution risk despite being an explicit declaration.
The package defines a post-autoload-dump lifecycle script. This is not inherently unsafe, but it adds install-time behavior that increases dependency integration and review requirements.
The source repository is owned by an individual user rather than an organization. That does not make the package unhealthy, but it indicates a thinner visible backing model.
The package has 17 releases over about four years, but none in the last 12 months. The recent repository push provides some compensating maintenance evidence, but registry release activity has slowed materially.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push timestamp is compensating evidence, but current development activity remains unconfirmed.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.