The package has no README or tests, and all recent repository commits come from one contributor. MIT licensing, a small dependency surface, and organization backing provide useful transparency for this compact library.
68%
Total Score
83
100
71
83
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the missing README is a minor documentation gap for a library consumers must integrate.
The package is brand new, with only 2 releases and both released within the same day, so there is little evidence of long-term maintenance or release stability.
All 3 recent commits came from one contributor, creating concentration risk; organization ownership provides some handoff capacity but no second active contributor is shown.
Composer is used as the build tool, but no security scanning tooling is present. For this small package, that is a modest hygiene gap rather than a severe maintenance risk.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities, although the package is small and has a limited dependency surface.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gpio/contracts Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.