The README and exact-version release notes make the package easier to understand and adopt. MIT licensing and recent releases help, but the project still lacks visible security tooling and has a very small maintenance base.
64%
Total Score
50
81
50
The package runs a post-autoload-dump script during installation, adding execution during dependency setup and therefore a modest supply-chain hygiene concern.
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
The package is only 22 days old but has four releases, with a median interval of about 7 days; this shows active early development without yet demonstrating long-term continuity.
One contributor made 100% of the two recent commits, leaving no demonstrated handoff capacity if that maintainer becomes unavailable.
Only two commits were recorded in the last three months, all from one active maintainer. The recent push is encouraging, but the small volume limits evidence of sustained maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
natilosir/bot Version * | — | — |
natilosir/verta Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.