Its README and release notes provide basic consumer context, and the MIT license is clear. Lack of tests and security scanning makes maintenance harder to verify.
38%
Total Score
0
67
50
The package has only three releases, with none in the last 12 months; its latest release was about 11 years ago. This strongly indicates abandonment risk, despite the package not being deprecated.
The repository recorded no commits or active maintainers in the last three months, consistent with the release history showing no update for about 11 years. The repository is not archived, but there is no observed maintenance activity.
The repository has zero stars and forks and only one watcher. Popularity is not decisive by itself, but these counters provide little supporting evidence of community adoption or review.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, especially for a package with no recent maintenance activity.
Version 0.2.0 is not a stable major release, which limits maturity evidence. It is not marked as a prerelease, but the long-standing 0.x version adds caution for a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webcms2/webcms2 Version ~0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.