The package has a very small source tree, no tests, and no security policy. Its license, matching repository, and GitHub release provide useful transparency, but there has been no recorded release or commit activity since 2016.
38%
Total Score
0
100
67
75
This is the only release, published over 10 years ago, with no releases in the last 12 months. That strongly suggests the package is abandoned or no longer maintained.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the very old release history and indicating no current maintenance.
The package has a README and a GitHub release, but neither the artifact nor repository has tests or a changelog. The short README also limits consumer documentation, though the release itself is documented as a GitHub release.
The repository has zero stars and one fork, providing little evidence of community adoption or external review. Popularity is only supporting evidence, so this reinforces rather than determines the maintenance concern.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, although the package has no recorded lifecycle install scripts.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
samsonos/js_core Version * | — | — |
samsonos/cms_input Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.