The repository includes tests, a matching README, a stable MIT license, and a release note for this version. Maintenance has slowed substantially, and the project has no security policy or security scanning, which increases long-term dependency risk.
55%
Total Score
33
100
72
75
The package has had only two releases, with the latest in January 2019 and none in the last seven years. This is a substantial maintenance concern for a dependency, despite the stable release history being consistent rather than erratic.
There were no commits and no active maintainers in the last three months, indicating that current maintenance activity has effectively stopped. The repository's last push in December 2022 does not compensate for the long recent inactivity.
The repository is owned by an individual rather than an organization, so there is no demonstrated organizational backing to compensate for the single registry maintainer and limited activity. This modestly increases continuity risk.
There are no open issues or pull requests and no activity in the past month. This is consistent with a quiet, mature project but also offers no evidence of active maintenance to offset the stale release history.
The repository has five stars, two forks, and one watcher, showing a small user and contributor footprint. Low popularity is only supporting evidence, but it provides little external maintenance resilience.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kylekatarnls/coffeescript Version ^1.0 | — | — |
nodejs-php-fallback/nodejs-php-fallback Version ^1.2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.