The source repository is present, unarchived, and matches the package, with tests, a README, release notes, and a clear MIT license. Maintenance capacity is uncertain because no release has appeared for about 8 years, recent commit activity is absent, and the repository has no security scanning or policy.
62%
Total Score
50
50
81
75
The package has 13 releases but none in the last 12 months, and its latest release was about 8 years ago. This is the strongest evidence of stale maintenance, despite the earlier release history.
The package declares 24 runtime dependencies, including substantial frontend and framework components. This breadth increases maintenance exposure, although the signal does not show those dependencies are currently unsafe or stale.
The repository is owned by an individual rather than an organization, so the single registry maintainer does not benefit from visible organizational backing. This modestly increases continuity risk.
The repository recorded zero commits and zero active maintainers in the last 3 months. This conflicts somewhat with the recent push timestamp but still indicates no demonstrated ongoing development in the measured window.
Composer is used for builds, providing basic reproducibility support, but no security scanning tool is configured. The missing scanning is a modest transparency and maintenance gap rather than proof of a defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dojo/dojo Version ~1.11 | — | — |
dojo/util Version ~1.11 | — | — |
wcmf/wcmf Version ~4.1 | — | — |
dojo/dijit Version ~1.11 | — | — |
dojo/dojox Version ~1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.