npm JSCPD plugin for PHPCI
35%
Total Score
unhealthy
Risky: no release since 2016 and no license leave this dependency effectively abandoned and legally unclear.
The latest release was in May 2016, about 10 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk despite the six historical releases.
No license is declared, and neither the package nor the linked repository contains a license file. This leaves developers without clear permission to use, modify, or redistribute the package.
The repository has only 1 star, 1 fork, and 1 watcher. Low popularity is supporting evidence rather than a verdict, but it provides little evidence of broad review or community resilience.
The linked repository is not archived, which is a small positive, but it was last pushed in May 2016 and therefore does not offset the prolonged inactivity.
The repository has no security policy. For a small, inactive plugin this reduces transparency and gives maintainers no visible process for handling issues.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.