It has a usable README and a small, explicit dependency set. The single maintainer and absent security policy add little confidence for a long-term dependency.
42%
Total Score
50
100
67
50
This is a five-year-old package with only one release and none in the last 12 months, which strongly indicates abandonment risk.
A proprietary license is declared in the manifest, so the release is licensed; however, its terms may constrain use or redistribution compared with a permissive open-source license.
Only one registry publishing account is listed, leaving limited visible publishing redundancy for a package that has already gone years without a new release.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the single-maintainer profile.
The repository has zero stars and forks and only one watcher, providing little supporting evidence of community adoption or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
npm-asset/leaflet Version ~1.0 | — | — |
composer/installers Version ^1.0.8 | — | — |
npm-asset/leaflet.markercluster Version ~1.0 | — | — |
npm-asset/leaflet.awesome-markers Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.