Clear documentation, tests, licensing, and frequent releases support adoption. The repository is organization-backed, but all recent commits come from one contributor and workflow actions are unpinned. No security policy adds a smaller transparency gap.
68%
Total Score
67
100
50
One contributor holds all recent commits, creating a meaningful continuity risk; organization ownership provides some capacity for handoff but does not demonstrate a second active maintainer.
Eight commits in the last three months show ongoing work, but all activity came from one active maintainer, limiting demonstrated maintenance depth.
The repository has no published security policy. This is a transparency gap for a database library, although it is not evidence of a security defect.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both action references are unpinned, leaving avoidable CI supply-chain drift.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
georgeff/kernel Version ^1.7 | — | — |
georgeff/database Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.