The MIT license, small dependency set, matching repository, and release notes make the package understandable to adopt. Missing security scanning and policy add maintenance uncertainty, while the single publisher limits visible continuity.
38%
Total Score
50
100
72
83
The package has only 3 releases, all clustered in 2016, with no release in more than 10 years. This is strong evidence of abandonment risk despite the stable version.
There were zero commits and zero active maintainers in the last 3 months, consistent with the package's more-than-10-year release gap and increasing abandonment risk.
Only one registry publisher is listed, which limits visible publishing continuity; organization backing in the linked repository partly compensates.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with an inactive project, though it does not show unresolved maintenance work.
The repository has 1 star and no forks, indicating limited adoption evidence. Popularity is supporting evidence only and cannot establish package quality by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kunstmaan/tagging-bundle Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.