The package has clear documentation, an MIT license, a matching source repository, and no install-time scripts. Maintenance evidence is thin, with no commits in the last three months and no releases in the last year; the missing security policy adds a smaller transparency concern.
58%
Total Score
50
100
83
83
One registry publishing account is listed. This is a limited publishing base, but the matching repository provides additional evidence of an identifiable project owner.
The package and repository are owned by the same individual account, providing consistent ownership but not organizational backing.
The package has 11 releases over about two years, but none in the last year. That long pause is a meaningful maintenance concern despite the earlier regular release interval.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the lack of recent releases, this points to weak current maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this modestly reduces confidence in project maturity but does not decide the result.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vuthaihoc/moox-core Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.