According to this report, there are two vulnerable dependencies and several outdated once.
Also, the library has compile dependencies on Maven Plug-in API. There is zero evidence that any on the Java code uses Maven code:
https://github.com/search?q=repo%3Avinyldns%2Fvinyldns-java+%28maven+OR+plexus%29&type=code
It should be removed because it brings unnecessary transitive dependencies into any runtime use of the library.
It seems to have been brought in with the very first commit:
7f38e12