The package has an Apache-2.0 license, tests, documentation, matching source, and no install-time scripts. Its very small, single-owner project provides little evidence of ongoing maintenance or security oversight, so pinning it carries abandonment risk.
42%
Total Score
25
75
83
The package has made no release in over four years, despite having only three releases overall. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided maintenance signal compensates for this inactivity.
Only one registry account has publishing access. This is not proof of poor maintenance, but combined with the inactive repository it indicates a thin operational base.
The repository has 0 stars, 0 forks, and 1 watcher, offering little community evidence or external maintenance support. Popularity is only supporting evidence, but here it does not offset the inactivity.
The repository has no security policy, leaving no documented channel or process for reporting security issues. This is a transparency gap, though it is less serious than the maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nowise/uup-application-options Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.