It has a clear GPL license, a small dependency surface, and no install scripts. The organization-owned repository and package reference add traceability, but the missing security policy leaves less guidance for handling issues.
40%
Total Score
50
100
71
75
This package has only one release, published about eight years ago, with no releases in the last 12 months. That is strong evidence of an effectively abandoned release line.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance activity.
The repository has 2 stars, 0 forks, and 1 watcher. This is weak supporting evidence of limited adoption, though popularity alone does not determine package health.
The linked repository has no security policy, so consumers have no documented process for reporting or coordinating vulnerability fixes.
Version 0.1 is not a stable major release, and no later version exists to demonstrate maturation. This reinforces the maintenance concern but is less severe than the stale activity itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.