bacarin/bacatools 1.0.0 appears usable and reasonably transparent, with an MIT license, a coherent 19-file repository, documented functionality, and tests covering the source code. However, this is a brand-new release with no demonstrated release or maintenance history, no repository security policy or security scanning, and no adoption or contributor track record; the single-user ownership also provides limited evidence of long-term maintenance capacity. It is not deprecated or archived and has no install-time lifecycle scripts, but adoption should be accompanied by monitoring for follow-up releases and maintenance activity.
68%
Total Score
50
100
83
90
A single registry maintainer limits visible publishing redundancy, although the linked user-owned repository provides direct project ownership context; this remains a modest maintenance-capacity concern rather than a severe risk.
The repository is owned by a user rather than an organization, providing direct ownership but limited evidence of institutional backing or maintainer redundancy.
Only one release exists and the package is 0 days old, so there is no observed history demonstrating sustained maintenance, compatibility management, or dependable release practices.
There are no issues or pull requests and no activity in the last month; because the repository is newly created, this does not by itself demonstrate neglect, but it leaves maintenance responsiveness untested.
The repository has 0 stars, forks, and watchers. This is weak supporting evidence, but the package's 0-day age substantially explains the absence of adoption data.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.