The package lacks a README and has an unresolved proprietary-versus-MIT licensing mismatch. Organization backing and a matching repository help with traceability, but the absence of recent development and security documentation makes long-term maintenance uncertain.
40%
Total Score
50
67
50
This is the only release, published nearly three years ago, with no releases in the last 12 months. That is strong evidence of an inactive package rather than a mature release stream.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the nearly three-year gap since its last push. No provided activity signal compensates for this.
The artifact contains an MIT license file, but the manifest declares the package proprietary. That mismatch creates a material legal ambiguity even though a recognized license is present.
The package has no README, while tests and a changelog are absent in both the artifact and repository. Missing tests and changelog are normal for published artifacts, but the missing README reduces consumer transparency for this library.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less severe than the maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
quantaforge/support Version ^1.0.0 | — | — |
quantaforge/pipeline Version ^1.0.0 | — | — |
quantaforge/contracts Version ^1.0.0 | — | — |
quantaforge/collections Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.