Consumers get little documentation, and the package has no security policy or meaningful repository adoption. Its stable major version, small dependency surface, and lack of install scripts are positives, but they do not offset the transparency gaps.
38%
Total Score
50
100
61
83
The latest release was in June 2020, with zero releases in the last 12 months despite the package being over six years old. This is strong evidence of abandonment risk, although the package is not formally deprecated.
No registry license declaration, license file, or repository license file was detected. That leaves the legal terms for using the dependency unclear.
The artifact has no README, tests, or changelog, and the repository also reports none. Missing tests and changelogs are acceptable packaging gaps, but the absent README weakens consumer transparency for a module library.
The repository owner is a user account rather than an organization, so the available backing signal does not show organizational support. This provides little compensating evidence for the package's thin maintenance record.
The repository name does not match the package name, and no README mention was available. A name mismatch can be normal for a sub-package, but without a README reference the package-to-repository relationship is less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scancode/portal-module Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.