The MIT license, repository tests, and recent repository activity provide useful transparency. Security policy and automated security scanning are absent, so long-term maintenance assurance remains limited.
68%
Total Score
83
50
75
75
Six runtime dependencies create a meaningful dependency surface for this small hardware-integration library, though the indicator provides no evidence that any dependency is unsafe or unmanaged.
The package artifact has no README, tests, or changelog, but compiled or source library artifacts are not expected to carry tests or changelogs; repository tests are present, while the missing README modestly limits consumer guidance.
The package is only 52 days old with two releases, so its maintenance track record is still too short to establish maturity; the roughly six-day release interval shows initial activity but not durability.
All four recent commits came from one contributor, leaving maintenance highly concentrated; organization backing provides some ability to hand work off, but no second active contributor is shown.
Composer build tooling is present, but no security scanning tools are reported, leaving a preventive review gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gpio/i2c Version ^0.6.0 | — | — |
gpio/contracts Version ^0.6.0 | — | — |
fabricate/circuits Version ^0.6.0 | — | — |
fabricate/actuation Version ^0.6.0 | — | — |
fabricate/nuts-and-bolts Version ^0.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.