Its MIT licensing and package/repository match improve transparency, but the 17-character README limits integration guidance. The single maintainer and eight install-time lifecycle scripts add upkeep and installation risk.
35%
Total Score
0
63
50
The package has had only one release, on 26 October 2017, with no releases in nearly 9 years. This is strong evidence of abandonment for a dependency receiving ongoing use.
The repository recorded zero commits and zero active maintainers in the past 3 months, consistent with the last release being nearly 9 years ago. No provided activity signal compensates for this inactivity.
The package declares eight install- and update-time lifecycle scripts, including pre- and post-install hooks. This increases installation complexity and maintenance exposure without evidence here that the scripts are necessary or well maintained.
The package includes a very short 17-character README, which provides little guidance for a library consumer. Missing tests and a changelog are normal for published artifacts, while release notes for this version provide a small positive.
The repository has no security policy. For a package with no recent maintenance activity, this leaves vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
siriussupreme/sirius-queue Version ^1.0 | — | — |
siriussupreme/sirius-support Version ^1.0 | — | — |
siriussupreme/sirius-broadcast Version ^1.0 | — | — |
siriussupreme/sirius-container Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.