Usable with caveats: the package is clearly licensed, narrowly scoped, and backed by a matching organization repository, but it has had no commits for about seven and a half months after only two releases. Its tiny codebase and lack of tests or security tooling make ongoing maintenance harder to assess.
58%
Total Score
50
100
72
88
The repository recorded zero commits and zero active maintainers in the last three months, following no newer activity since the January release; this is the strongest maintenance concern.
A single registry publisher is a limited publishing base, but the repository is owned by the backing Flectar organization, which provides some compensation.
Only two releases have been published, with the latest about seven and a half months ago; this is limited maturity for a dependency, although the package is still relatively young.
There are no open issues and one open pull request, but no issues or pull requests were merged in the last month, offering little evidence of active maintenance.
The repository has only 1 star and 1 fork, indicating limited external adoption; popularity is supporting evidence rather than a decisive health measure for a small extension.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
waterhole/core Version ^0.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.