The project is only 106 days old and has three releases, so its long-term maintenance is unproven. An organization owns the repository, but one contributor made all three recent commits and there is no security policy or scanning.
63%
Total Score
75
100
75
75
The published artifact lacks a README, tests, and changelog, but the repository contains a README and these omissions are common for published source artifacts. The repository still reports no tests or changelog, limiting maintenance evidence.
The package is 106 days old with three releases and a median interval of about 28 days. This shows activity but leaves limited evidence of long-term maintenance.
One contributor made 100% of the three recent commits. Organization backing provides some continuity, but no second active contributor is shown to share the maintenance load.
Only three commits were recorded in the last three months, all from one active maintainer. That demonstrates recent work but is a thin maintenance track record.
Composer build tooling is present, but no security-scanning tools are detected, leaving fewer automated checks for dependency or code issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gpio/i2c Version ^0.6.0 | — | — |
gpio/contracts Version ^0.6.0 | — | — |
fabricate/circuits Version ^0.6.0 | — | — |
fabricate/nuts-and-bolts Version ^0.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.