Package Health

gpio/spi

The codebase is small and easy to inspect, with a clear MIT license and no install-time scripts. Its security documentation and independent maintenance coverage are limited, so pin v0.8.0 and watch future releases.

Latest v0.8.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Package scaffoldingcaution

The artifact has no README, while the repository also reports no tests or changelog. The small nine-file library is inspectable, but the missing consumer documentation reduces transparency.

Release historycaution

The package is brand new, with only two releases recorded on the same day and no demonstrated release cadence. That leaves maturity and long-term maintenance largely unproven.

Repo bus factorcaution

All four recent commits came from one contributor, leaving maintenance highly concentrated. Organization ownership provides some handoff capacity, but no second active contributor is shown.

Security policycaution

The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. For a package intended to integrate with hardware interfaces, this is a meaningful transparency gap.

Version stabilitycaution

v0.8.0 is not a stable-major release, so its API and behavior may still change substantially. It is not marked as a prerelease, which provides a small compensating signal.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Angel Gonzalez

Direct Dependencies

DependencyLast ReleaseScore
gpio/contracts
Version ^0.8.0
venusian-voyager/contracts
Version ^0.8.0
venusian-voyager/collections
Version ^0.8.0
venusian-voyager/magic-aliases
Version ^0.8.0
venusian-voyager/nuts-and-bolts
Version ^0.8.0

Weekly Downloads

Info

Last Published
5 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform