The source is a compact 24-file library with two runtime dependencies and no install-time scripts. It is not archived or deprecated, but the lack of security tooling and a single publisher leave limited evidence for long-term support.
58%
Total Score
67
100
75
88
One registry publisher is consistent with a user-owned project, but it also indicates a thin publishing base with limited visible redundancy.
The published artifact has no README, which makes a library harder for consumers to integrate; missing tests and a changelog are normal for a published artifact and are not gaps here.
The package has only three releases, all published within one day, so there is not yet enough history to demonstrate mature release practices or sustained maintenance.
No commits or active maintainers were recorded in the last three months. Because the repository was created on the release date, this chiefly shows that maintenance history is unproven rather than that activity has collapsed.
The repository name does not exactly match the package name, and no README evidence confirms the package relationship. A naming mismatch can be normal for a sub-package, but no such compensation is shown here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
niangpro/core Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.