The package is small, documented, and has no install-time scripts. Its long-unmaintained state and missing license make future fixes and safe legal adoption uncertain.
43%
Total Score
25
100
79
75
Only one release exists, published over eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk despite the stable v1.0 designation.
There were no commits and no active maintainers in the last three months. Combined with the old last push, this materially increases abandonment risk.
No license is declared, no license file is present in the package, and the repository also has no license file. This creates a genuine legal and transparency concern for adopters.
A single registry maintainer is consistent with a small user-owned project, but it leaves little visible publishing redundancy when combined with the lack of recent activity.
The repository has no security policy. For a package handling digital-certificate web-service integration, this weakens vulnerability-reporting transparency, though it is not evidence of a vulnerability itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.