The small, tested codebase and clear README support straightforward integration. Its proprietary licensing, single release from 2018, and absent recent commit activity make long-term adoption a liability.
46%
Total Score
67
100
63
83
The package has only one release, published about 7 years ago, with no releases in the last 12 months. This is strong evidence of limited ongoing maintenance despite the repository remaining available.
There were zero commits and zero active maintainers in the last 3 months. Combined with a single release from 2018, this indicates weak current maintenance capacity.
The manifest declares the package proprietary and no license file was found. That creates a meaningful adoption and redistribution constraint for an open-source dependency.
The repository name does not match the package name and its README does not mention the package. Although this can occur with subpackages, the lack of a README reference leaves some uncertainty that the repository is the intended source.
The repository has zero stars and one fork. Low popularity is only supporting evidence, but it offers little external evidence of broad adoption or review.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
tutu-ru/lib-request-metadata Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.