It has a readme, a real GitHub release, and organization backing. The short maintenance record and missing license make long-term adoption less clear.
55%
Total Score
75
86
83
Neither the package nor the linked repository declares or contains a recognized license file. This creates a real adoption and legal-transparency gap.
The package has five releases in about eight months, but the latest release was about four months before collection, leaving limited evidence of continued maintenance.
The repository recorded 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance concern for a package released only a few months ago.
The linked repository has no security policy. This is a modest transparency gap, though the package is not deprecated or archived.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bower-asset/jquery Version 3.7.1 | — | — |
bower-asset/jstree Version 3.3.17 | — | — |
bower-asset/store2 Version 2.14.4 | — | — |
bower-asset/toastr Version 2.1.2 | — | — |
bower-asset/bootbox Version 6.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.