The project includes tests, a clear MIT license, and release notes for this version. Its workflow uses insecure commands and unpinned actions, adding maintenance and build-integrity concerns alongside the long release gap.
56%
Total Score
33
100
83
75
The latest release was published nearly 6 years ago, with no releases in the last 12 months. This is a substantial maintenance concern for a library dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the risk of stalled maintenance.
The repository is owned by an individual account, so the small two-account registry maintainer list does not benefit from organization backing; this offers limited maintenance capacity.
There are open issues and pull requests, but none were opened, closed, or merged in the last month, indicating limited current triage.
No security policy was found, leaving maintainers' vulnerability-reporting process unclear for a library that parses external input.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vipnytt/useragentparser Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.