The linked project has recent commits, release notes, a README, and dependency scanning, but all recent commits come from one contributor. Use medcore-ua/nk-025-2021-parser instead.
20%
Total Score
83
100
75
75
Packagist marks the package abandoned at package scope and explicitly names medcore-ua/nk-025-2021-parser as the replacement. This makes the assessed package an unsuitable dependency despite other healthy project signals.
The package is only 300 days old with two releases, including one within the last year; this shows some activity but limited release history and maturity.
All 10 recent commits came from one contributor, so maintenance depends on a single active person. Organization ownership provides some handoff capacity but does not remove the concentration concern.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though it is secondary to the package abandonment status.
Version v0.2.0 is not a prerelease, but the 0.x major version signals an API that may still change and is less mature than a stable-major release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.