Its dependency footprint is small, the version is stable, and it has no install-time scripts. Documentation and security transparency are limited, making long-term support and safe integration harder to verify.
42%
Total Score
50
100
61
75
The package has 21 releases, but none in the last 12 months and its latest release was in October 2020, indicating roughly five years of inactivity. The earlier release cadence shows it was once maintained, but does not offset the prolonged gap.
No license is declared, no license file is present in the artifact, and the repository also has no license file. This leaves the legal terms for using the package unclear.
The published artifact has no README, while the collected repository metadata also shows no tests or changelog. Tests and changelogs are normal source-repository concerns, but the missing package README makes integration less transparent.
The repository owner is a user account rather than an organization, and the provided backing data does not show organizational ownership. This offers less visible continuity than an explicitly backed project.
The repository name does not match the package name, and no README mention was found. A sub-package can legitimately use a differently named repository, but the available evidence does not clearly connect this repository to the published package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scancode/portal-module Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.