The EULA declaration has no accompanying license file, and the repository has no security policy. Organization ownership and a matching repository provide some accountability, but do not offset the lack of recent maintenance.
40%
Total Score
100
50
83
The latest release was published nearly six years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a package developers may need to maintain or integrate.
The package declares an EULA, so it has a licensing declaration, but no license file was detected in the package or repository. The declaration may still be restrictive or unclear to downstream users.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than decisive, but these counts provide no visible community support to offset the stale activity.
The repository is not archived, which keeps the project technically available, but its last push was nearly seven years ago and does not show active maintenance.
No security policy was found in the repository. This is a transparency and maintenance gap, though it is less important than the long absence of releases and commits.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.