atoms/core appears suitable for dependency use: it is actively releasing, not deprecated or archived, has a clear MIT license, a small and focused dependency surface, tests in both the artifact and repository, and recent activity from two contributors under an organization-owned project. The package is young at 22 days and remains on a pre-1.0 version, while the repository has no security scanning or security policy and no changelog; these are meaningful transparency and process gaps, but they do not outweigh the strong evidence of current maintenance and coherent project backing. Popularity is currently negligible, though that is supporting evidence rather than a decisive concern.
82%
Total Score
100
100
83
90
The repository has zero stars, forks, and watchers. This provides little external validation, but popularity is supporting evidence and the package has stronger direct maintenance signals.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a process gap, though it is not evidence of abandonment by itself.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap for a runtime library.
Version 0.6.0 is not a stable major release, so API compatibility may still evolve, but it is not marked as a prerelease and recent versions show a consistent release pattern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.