The project is very young, with one release and only two recent commits. Its organization backing and MIT license help, but the missing README and security policy leave useful adoption and maintenance information undocumented.
64%
Total Score
63
100
75
75
Only one registry account has publish access. The organization-owned repository provides some backing, but registry publishing remains concentrated.
No README, tests, or changelog are present. Missing tests and changelog are normal for a published artifact, but the absent README is a minor consumer-documentation gap for this integration library.
This is a young package released 41 days ago with only one release, so there is not yet enough history to demonstrate sustained maintenance or release reliability.
All two recent commits came from one contributor. Organization ownership partly reduces handoff risk, but no second active contributor is evidenced.
The repository recorded two commits in the last three months, showing some activity but a very limited maintenance track record.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fabricate/database Version ^0.7.0 | — | — |
fabricate/contracts Version ^0.7.0 | — | — |
fabricate/nuts-and-bolts Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.