Usable with caveats: the release is licensed, non-deprecated, clearly backed by a matching repository, and was updated recently. It is only 15 days old, has just two recent commits from one contributor, and lacks a security policy, so long-term maintenance is not yet proven.
68%
Total Score
60
100
88
90
Only one registry account has publish access. That is a limited publishing base, and the user-owned repository provides no organizational backing to offset the concentration.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization; this does not provide additional maintenance redundancy.
The package is only 15 days old with three releases, so its maintenance record is too short to establish maturity, although releases have arrived about every 8 days.
All two recent commits came from one contributor, leaving no demonstrated backup for maintenance if that contributor becomes unavailable.
The repository has two commits in the last three months and was pushed recently, showing some current maintenance but a very small activity record.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
natilosir/bot Version * | — | — |
natilosir/verta Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.