The repository has organization backing and was updated recently, but only one contributor made two commits in the last three months. The package has no tests or security policy, limiting confidence in long-term maintenance.
67%
Total Score
67
100
71
75
The published artifact has no README, tests, or changelog, while the repository does contain a README. Missing tests and a changelog reduce project maturity evidence, although their absence from the artifact is normal packaging practice.
The package is 54 days old with two releases, both published almost immediately apart, so there is little release history to demonstrate sustained maintenance.
One contributor made all commits in the last three months, creating a concentrated maintenance dependency. Organization backing provides some handoff capacity, but no second active contributor is shown.
Only two commits were made in the last three months, which shows some recent activity but a thin maintenance record for a package released 54 days ago.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gpio/i2c Version ^0.6.0 | — | — |
gpio/digital Version ^0.6.0 | — | — |
gpio/contracts Version ^0.6.0 | — | — |
fabricate/circuits Version ^0.6.0 | — | — |
fabricate/nuts-and-bolts Version ^0.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.