The project has one publisher and no documented security process. Its small, tested repository and clear licensing provide useful transparency, but not enough evidence of ongoing support.
42%
Total Score
50
79
75
This is the package's only release, published nearly 9 years ago, with no releases in the last 12 months. The stable version and available source do not offset the strong abandonment concern.
Only one registry publisher is listed. That is not proof of poor ownership, but combined with the lack of recent releases it leaves little visible maintenance capacity.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with a dormant project, although a small package may naturally receive little community traffic.
The repository is not archived, which is a positive counter-signal, but it was last pushed nearly 9 years ago and therefore shows no recent maintenance.
The repository has no security policy or documented reporting process. For a package that handles server functionality, this reduces transparency around vulnerability response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
anax/di Version ^1.0 | — | — |
anax/url Version ^1.0 | — | — |
anax/view Version ^1.0 | — | — |
anax/router Version ^1.0 | — | — |
anax/request Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.