Usable with caveats: the package is small, licensed, tested, and not deprecated, but it has had no release or commit activity for nearly three years. Verify that the linked repository is the intended project because it neither matches the package name nor mentions it in its README.
58%
Total Score
67
80
Only one registry account has publish access, which creates a narrow operational base. The organization-owned repository provides some backing, so this is a moderate concern rather than a severe one.
Only two releases were published, with none in the last 12 months; the latest release is nearly three years old. This indicates a largely inactive project, although the package may be stable if its narrow utility scope has not changed.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long gap since the latest release. This weakens evidence of ongoing maintenance.
The repository name does not match the package name and its README does not mention the package, creating uncertainty that it is the intended source repository. The matching organization owner provides some context but does not resolve that transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
querypath/querypath Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.