The package has a license, a small dependency surface, and no install-time scripts. Its minimal repository has no security policy or automated workflows, so ongoing care and release safeguards are limited.
38%
Total Score
100
69
67
This release is the package's only release, published about six years ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
The repository name does not match the package name and its README does not mention the package. That raises uncertainty about whether the linked repository is the package's actual source.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of an active user or contributor base.
The repository is not marked archived, but it was last pushed about six years ago, reinforcing the evidence of inactive maintenance.
The repository has no security policy. This is a transparency and response-process gap, although it is less significant than the long period without releases or commits.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
snanword/think_framework Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.