Risky to adopt for a new project because the latest release and repository activity are about 10 years old. The package is clearly identified, licensed, tested, and not deprecated or archived, but its one-person ownership and long inactivity make future fixes uncertain.
43%
Total Score
33
100
72
88
The package has 12 releases, but its latest release was about 10 years ago and it has had no releases in the last 12 months, indicating substantial abandonment risk despite its earlier release history.
There were no commits and no active maintainers in the last three months, consistent with the roughly 10-year-old last release and making fixes or compatibility updates uncertain.
Only one registry maintainer is listed, leaving a thin publishing and maintenance base; the repository is user-owned rather than organization-backed, so there is no shown organizational capacity to compensate.
The registry namespace and repository owner match, but both identify an individual user rather than an organization, leaving limited visible backing for long-term maintenance.
The repository has only 2 stars and no forks, providing little evidence of a broad user or contributor community to help sustain it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openlss/lib-array2xml Version 0.0.x | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.