Documentation and maintenance capacity are limited. The package has no license, no tests, no changelog, and no security policy, increasing adoption and long-term support risk.
32%
Total Score
50
100
50
83
No license declaration or license file was detected in the package or repository, leaving developers without clear permission to use or redistribute the code.
The latest release was published over six years ago, with no releases in the last 12 months; this is strong evidence of abandonment risk despite a historically regular early cadence.
The published artifact has no README, tests, or changelog, and the repository also reports none. Missing tests and changelog can be normal for packages, but the absent consumer documentation is a meaningful transparency gap for a framework module.
The repository owner is a registry user account rather than an organization, so the single maintainer is not supported by visible organization backing in this signal.
The repository name does not match the package name, and no README mention was available, so the linkage is less transparent even though a sub-package or module naming difference could explain it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scancode/portal-module Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.