Clear documentation, tests, licensing, and a matching repository make integration and provenance straightforward. Its narrow dependency profile and recent commits are reassuring, while the limited project history leaves less evidence of long-term support.
72%
Total Score
67
100
81
100
The repository is owned by a user rather than an organization, so the one-person maintenance concentration is not offset by visible organizational backing.
The package is only 62 days old with three releases and a median interval of about 16 days. That shows active early development but provides limited evidence of long-term maintenance.
All five recent commits came from one contributor, leaving maintenance dependent on a single active developer and increasing continuity risk.
Composer build tooling is present, but no security-scanning tool was detected, leaving repository-level security checks less visible.
Version v0.3.0 is not marked as a prerelease, but the pre-1.0 major version signals an API that may still evolve substantially.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
innis/nostr-core Version ^0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.