Documentation and test coverage support day-to-day adoption. The organization provides some continuity, but the narrow contributor base and absent security policy leave moderate maintenance risk.
72%
Total Score
67
93
75
One contributor made all 13 commits in the last 3 months. The organization-owned project provides some handoff capacity, but no second recent contributor is visible, so continuity risk remains.
The repository received 13 commits in the last 3 months, showing ongoing work rather than abandonment. However, all recent activity comes from one active maintainer, which limits resilience.
The repository name matches the package, but its README does not explicitly mention the package name. That creates a modest ownership or packaging-transparency concern despite the matching repository name.
The repository has no security policy. This does not show a security defect, but it leaves vulnerability reporting and response expectations unclear for a package used in applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cognesy/agents Version ^2.11 | — | — |
cognesy/logging Version ^2.3 | — | — |
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
cognesy/agent-ctrl Version ^2.8 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.