The package includes tests, release notes, a clear MIT license, and a small dependency surface. Its source has seen no commits for nearly seven years, and the project has little community activity or security-process evidence.
42%
Total Score
0
100
75
75
The latest release was in May 2016, with no releases in the following 12 months or since; this is a substantial maintenance and compatibility risk despite six historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was nearly seven years ago; this strongly suggests the project is no longer maintained.
The repository has one star, zero forks, and one watcher, indicating very limited visible adoption and support; this reinforces the maintenance concern but is not decisive alone.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a secondary transparency gap for a library with no recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phossa/phossa-shared Version >=1.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.