The project has organization backing and a clear MIT license. Its very short history, single active contributor, missing README, and absent security policy leave maintenance and consumer guidance uncertain.
62%
Total Score
75
80
75
The package has no README, which limits consumer guidance for an encryption library. The absence of tests and a changelog is normal packaging practice and does not lower the score.
The package is only 43 days old and has one release, so there is little evidence of sustained maintenance or release stability.
Only one contributor made the two commits in the last three months, with all activity concentrated in that person. Organization backing helps, but no second active contributor is shown to provide handoff capacity.
The linked repository has no security policy, leaving vulnerability reporting and response expectations unclear for a security-sensitive library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fabricate/contracts Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.