The package offers little consumer documentation and no security policy, while its tiny repository gives limited evidence of ongoing care. MIT licensing, stable versioning, and no install scripts are positives.
52%
Total Score
0
69
75
The latest release was nearly seven years ago, with no releases in the last 12 months and only two releases overall. This is strong evidence of an unmaintained dependency, although the package is not registry-deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This materially raises abandonment risk.
The published artifact has no README, which is a documentation gap for a library consumers must integrate with. Missing tests and changelog files are normal packaging practice, while a GitHub release exists for this version.
The repository has only 2 stars and 2 forks, providing little community evidence or support capacity. Low popularity is supporting caution rather than a verdict by itself.
The repository is not archived, which preserves a path for maintenance, but its last push was in December 2019 and does not offset the extended inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
knplabs/knp-snappy Version ^0.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.