The package declares MIT licensing, but its included notice refers to LGPL and the repository has no license file. It also lacks security scanning and has no recent workflow or release documentation to offset the maintenance concerns.
38%
Total Score
33
67
75
Only three releases were published, with no releases in the last 12 months; the latest registry release is roughly 11 years old. This is strong evidence of abandonment for a package intended as an application dependency.
There were zero commits and zero active maintainers in the last three months, after the repository's last push roughly 11 years ago. This is the clearest evidence that fixes and maintenance are unlikely.
The manifest declares MIT, so the release is not unlicensed, but the packaged README excerpt contains an LGPL notice and no license file was found. That creates a meaningful licensing ambiguity for consumers.
The repository owner is an organization, which can provide some backing beyond an individual publisher. However, the observed release and commit activity shows no active maintenance capacity.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with an inactive project, though the absence of open work is not harmful by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.