The package is licensed, documented, and backed by an organization, with repository tests and no install-time scripts. Its short history leaves limited evidence of long-term maintenance. A security policy is also absent.
68%
Total Score
67
100
83
83
The package is only 46 days old and has three releases, all within a 2-day window, so there is limited evidence of sustained maintenance beyond its initial launch.
All five recent commits came from one contributor, leaving maintenance dependent on a single active person. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository recorded five commits in the last three months, showing recent activity, but only one active maintainer contributed them.
The repository has no security policy. This is a transparency gap for reporting and handling vulnerabilities, though it is not evidence of a vulnerability itself.
Version 0.7.2 is not marked as a prerelease, although the package remains below 1.0 and may still undergo breaking changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
microscrap/glfw Version ^0.7.0 | — | — |
microscrap/open-gl Version ^0.7.0 | — | — |
scrapyard-io/tubes Version ^0.7.0 | — | — |
fabricate/nuts-and-bolts Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.