The project includes tests, release notes, and organization backing, but its registry history has only one release and no commits in the past three months. Install-time scripts, an MIT repository license conflicting with the Apache-2.0 declaration, and broad unpinned workflow configuration add maintenance and supply-chain concerns.
58%
Total Score
83
50
75
50
Seven runtime dependencies, including the OpenTelemetry stack and an extension requirement, create a meaningful dependency surface for this small package, though the dependencies fit its instrumentation purpose.
The package declares Apache-2.0, while the repository license file is detected as MIT, so the licensing information is inconsistent even though both sides provide a license.
post-install-cmd and post-update-cmd scripts run during dependency installation or updates, increasing operational and supply-chain exposure compared with a package without lifecycle hooks.
The package is 389 days old but has only one release and no releases in the past 12 months, leaving little evidence of sustained release maintenance.
There were no commits and no active maintainers during the past three months, a meaningful warning for a package with only one registry release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/cache Version ^1.2 | — | — |
open-telemetry/api Version ^1.0 | — | — |
open-telemetry/sdk Version ^1.0 | — | — |
open-telemetry/context Version ^1.2 | — | — |
open-telemetry/sem-conv Version ^1.32 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.