The package is small and transparent, with an MIT license, a matching repository, and clear usage instructions. Its single maintainer and absent security policy leave little operational depth if maintenance is needed.
42%
Total Score
0
70
50
This is the package's only release, published in November 2016, with no releases in the last 12 months. That long period without a new release is strong evidence of abandonment risk, although a small stable asset package may need few updates.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the package having been untouched since November 2016. There is no observed maintenance capacity to offset the age of the release.
The repository has 0 stars and 0 forks, with only 2 watchers. Popularity is not decisive for a small package, but this provides little supporting evidence of ongoing community attention.
The linked repository has no security policy. This is a transparency and response-process gap, though the package's small scope and lack of lifecycle scripts limit the practical exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version >=2.0.0 | — | — |
bower-asset/html5shiv Version 3.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.