The repository has no security policy or security scanning, and one maintainer offers limited support capacity. The package is small and clearly identified in its repository, but its licensing and age make long-term adoption difficult.
35%
Total Score
25
60
75
The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. This creates a significant legal and transparency risk for an open-source dependency.
There has been only one release, published over 9 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, and its last push was in 2017. The long-standing lack of activity is not offset by the repository merely remaining unarchived.
The package has one registry maintainer. The matching user-owned repository provides some accountability, but the narrow maintainer base increases continuity risk.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a maintenance and transparency gap for a package that pushes application error events.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.