The package has a very small user footprint and no security policy or automated tests. Its MIT declaration, readme, and single runtime dependency provide some transparency, but this old release carries substantial maintenance risk.
40%
Total Score
0
100
71
50
The latest release was published in November 2019, and there were no releases in the following 6 years 10 months. This strongly raises abandonment risk for a library dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long period since the last release. There is no observed recent maintenance to offset the age of version 0.0.3.
The linked repository name does not match the package name and its README does not mention this package. That weakens confidence that the repository is the package's clearly maintained home.
The repository has 6 stars and 1 fork, providing little evidence of a broad user or contributor community. This supports the maintenance concern but is not decisive by itself.
The linked repository has no security policy. For a package that handles HBase access, this reduces transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
packaged/thrift Version ^0.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.