MongoDB adapter package for domainflow/event-sourcing-core
68%
Total Score
75
86
67
This package is 31 days old and has only one release, so there is little evidence yet of sustained maintenance or release stability.
All three commits in the last three months came from one contributor, creating concentrated maintenance risk; the organization-owned repository provides some capacity to hand off work.
No security policy is present in the repository, leaving vulnerability reporting and response expectations undocumented.
Version v0.1.0 is an early non-stable-major release, which indicates a higher likelihood of API or behavior changes for adopters.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or high-severity issues. However, all 25 action references are unpinned, which weakens build reproducibility and supply-chain integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mongodb/mongodb Version ^2.0 | — | — |
domainflow/event-sourcing-core Version ^v0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.