Its install-time script and lack of security scanning add maintenance and review overhead. The MIT license, small dependency footprint, and matching source repository provide useful transparency.
35%
Total Score
25
100
56
50
The package has made only one release, on 30 May 2015, with no releases in the last 12 months. That long-standing lack of release activity is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last three months. Together with the old last push and one-release history, this indicates a strong abandonment risk.
The repository is not archived, but its last push was on 24 November 2015. The unarchived status does not compensate for the prolonged inactivity.
The package runs a post-create-project-cmd script during installation. This is relevant execution behavior that increases review and maintenance overhead, though it is not by itself evidence that the package is unsafe.
A README is present, while absent tests and changelog files are normal for published package artifacts and are not treated as gaps here. The short README limits consumer guidance but is only a minor concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vccw-team/vccw Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.