The MIT license, repository tests, and organization backing provide useful transparency. A missing security policy and one registry publisher leave limited visible stewardship.
58%
Total Score
83
100
75
50
The latest release was in December 2020, about 5 years and 9 months before collection, with no releases in the last 12 months. This is strong evidence of an aging package.
Post-install and post-update scripts run during dependency operations, adding some installation complexity and supply-chain exposure, though no harmful behavior is shown here.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with a project that is no longer actively maintained.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
Version v0.2.1 is not a stable major release, so its API and maintenance maturity are less established than a 1.x release. It is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yawik/jobs Version ^0.35 | — | — |
beberlei/assert Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.