The small codebase has a clear license and one runtime dependency. Organizational ownership and a matching repository provide useful context, but ongoing maintenance signals are limited.
63%
Total Score
75
93
50
The package has four releases over about three years, but none in the last 12 months; the latest release was about 19 months ago. This indicates slowing maintenance, though the package is not abandoned outright.
There were no commits or active maintainers in the last three months. This is a meaningful maintenance concern, although the repository had a more recent push and the package is small.
The linked repository has no security policy. That lowers transparency for reporting and handling vulnerabilities, especially for a package that changes comment behavior in consuming applications.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mecha-cms/x.comment Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.