The MIT license, clear README, repository tests, and matching package mention provide a useful baseline. A single registry maintainer, no security policy or scanning, and no recent issue activity leave limited visible support for future fixes.
42%
Total Score
63
50
78
50
The package has had no release in nearly nine years, despite 25 historical releases; this is strong evidence that maintenance has stopped.
There were zero commits and zero active maintainers in the last three months, consistent with the release history and indicating little current capacity to fix defects.
Six runtime dependencies create a meaningful dependency surface for a small common library, but the signal provides no evidence that the dependencies are unsafe or unmanaged.
Five issues remain open, with no new or closed issues and no pull-request activity in the last month, suggesting limited ongoing maintenance or support.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little external evidence of ongoing adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
seld/jsonlint Version 1.1.*@stable | — | — |
webforge/utils Version ~1.1.0@stable | — | — |
webforge/process Version 1.2.*@dev | — | — |
webforge/collections Version 1.0.*@stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.