The artifact is documented, has release notes, and is not archived or deprecated. The license metadata conflicts with the detected artifact license, and the repository has had no commits in the last three months. Pin this version while confirming which license governs the package.
65%
Total Score
50
100
81
88
The manifest declares GPL-2.0-or-later and the artifact contains license files, so the release is licensed, but the detected MIT license does not match the declaration. The mismatch warrants checking the licensing of the distributed code.
The package and repository are owned by the same individual account, so the single registry maintainer is consistent with the project's backing rather than evidence of a hidden organization mismatch. This still represents a narrow maintainer base.
The package has existed since October 2020 and has 9 releases, but it has had no registry release in the last 12 months. That indicates slowing maintenance, although the latest release is still relatively recent.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, even though the repository was pushed in November 2025.
There are no open issues and one open pull request, with no new or merged pull requests in the last month. The absence of issues is positive, but the lack of recent merging offers little evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yahnis-elsts/plugin-update-checker Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.