Web version of the finger protocol
78%
Total Score
75
100
89
80
Only one registry account has publish access, creating some continuity risk; the matching user-owned repository and recent release activity provide partial context but do not remove the single-maintainer dependency.
The package has existed for over 11 years and released this version recently, but only four total releases and a median interval of about 440 days indicate a deliberately slow release cadence.
No commits or active maintainers were recorded during the last three months, which is a meaningful maintenance concern, although recent merged pull requests and the current release show the repository has not been abandoned.
The repository has only 3 stars and no forks, so external adoption and community redundancy appear limited; popularity is supporting evidence rather than a decisive health measure.
The repository has no security policy, leaving vulnerability reporting guidance undocumented; this is a transparency gap, but not by itself evidence that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mf2/mf2 Version ^0.5.0 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
barnabywalters/mf-cleaner Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.