The repository contains tests and the release uses no install-time scripts, reducing operational risk. No security scanning or security policy is present; confirm permitted use and provenance before adopting it.
42%
Total Score
50
100
56
83
The manifest declares the package proprietary, with no detected license text or license file. That creates a significant legal barrier for a dependency described as open source.
The package includes tests and the repository includes tests, which supports basic project maturity. The missing package README is a minor consumer-documentation gap for a library.
The package has existed for about 6 years 5 months but has only 8 releases, with a median interval of about 279 days and one release in the last 12 months. This indicates a slow maintenance cadence, although a recent release exists.
There were 0 commits and 0 active maintainers in the last 3 months. The release was published recently, but the lack of observed ongoing activity raises maintenance risk.
The repository name does not match the package name, and no README mention was available. The mismatch may be normal for a sub-package, but the missing corroboration weakens provenance confidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
micro-module/saga Version ^0.6.0 || ^0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.