Its MIT license, small transparent artifact, and release notes are positives. The lone maintainer and absent security tooling leave limited evidence for ongoing support.
18%
Total Score
25
63
50
Packagist marks the entire package abandoned and names sbuerk/repo-new as its replacement, making this release unsuitable for a new dependency.
The package has had no releases in about 21 months, and its seven releases were concentrated in a brief initial period; this supports an abandonment concern.
The linked repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current maintenance.
Only one registry account has publishing access. The small package size reduces operational burden, but there is little visible publishing redundancy if that maintainer stops.
The linked repository is named repo-new rather than repo-old and does not mention this package in its README, so its relationship to this release is unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.