A single publisher and no security policy leave little evidence of ongoing support. The small dependency surface and non-archived repository reduce, but do not remove, adoption risk.
38%
Total Score
50
100
56
83
The package has had no release in nearly seven years: its latest release was December 17, 2019, and it has had zero releases in the past 12 months. This is strong evidence of abandonment risk.
No license is declared, and neither the package nor the linked repository contains a license file. That leaves the terms for reuse unclear.
Only one registry account has publish access. A single maintainer can be sufficient for a small package, but here it provides little resilience alongside the long release gap.
The package has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the missing README reduces transparency for a library consumers must integrate.
The repository owner is recorded as a GitHub User rather than an organization, so there is no observed organizational backing to compensate for the single registry maintainer and stale activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scancode/portal-module Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.