Documentation and validation coverage are limited, while the small dependency surface keeps integration simple. Organization backing and a recent repository push provide some continuity, but the project is too new for a strong track record.
60%
Total Score
67
100
75
50
The artifact and repository have no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README reduces consumer transparency for this library.
The package was first released today and has only two releases, so there is not yet enough history to demonstrate mature maintenance or stability.
One contributor made all recent commits, creating a concentrated maintenance risk. Organization ownership provides some ability to transfer maintenance, so this is a caution rather than a severe risk.
Only two commits were recorded in the last three months, indicating very limited observed maintenance activity; the repository was updated recently, which provides some counterweight.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented for dependents.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gpio/contracts Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.