The package is clearly identified and carries a usable README and license. Its pre-1.0 status and lack of tests leave limited evidence of maturity, while repository activity has stopped after the initial extraction. The organization backing and basic tooling help, but do not offset the thin maintenance record.
58%
Total Score
75
70
75
The package includes a README with installation and development instructions, but it has no tests or changelog. Missing tests reduce maturity evidence, while the absent changelog is normal packaging practice and the README is helpful.
All four releases arrived within about 2 hours, followed by no new release for about 7 months. This looks like an initial extraction burst rather than an established release cadence.
There were 0 commits and 0 active maintainers in the last 3 months, with the last repository push about 7 months ago. This is meaningful evidence of stalled maintenance for a package intended as reusable middleware.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the small package scope and Dependabot configuration provide some limited security-process support.
Version v0.2.2 is not on a stable major version, so the public API may still change. It is not marked as a prerelease, which provides a small compensating signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
denosyscore/cache Version ^0.2 | — | — |
denosyscore/contracts Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.