The package is proprietary and has no license file, limiting reuse clarity. The linked repository does not match the package name, adding uncertainty about provenance. Its small artifact also lacks a README for integration guidance.
28%
Total Score
50
58
100
The latest release was published in September 2017, with no releases in the last 12 months and only two releases overall. This is strong evidence of abandonment risk for a dependency.
A proprietary license is declared, so the release is licensed, but there is no license file and the terms may restrict ordinary open-source reuse. That creates a real adoption concern.
Only one registry account has publishing access, leaving little visible publishing redundancy. This is more concerning alongside the long period without a release.
The artifact has no README, which makes a small library harder for consumers to integrate. The absence of tests and a changelog is normal packaging practice and is not penalized.
The linked repository name does not match the package name, and no README mention was collected. A subpackage or naming difference is possible, but the package-to-repository relationship remains less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
xprt64/filesystem Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.