The package is newly published, with no demonstrated maintenance history yet. Its library artifact has no README, tests, changelog, or security scanning, while the repository is active and the MIT license is declared.
55%
Total Score
50
100
71
67
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README is a minor usability gap for a library consumers must integrate.
The repository is owned by a personal account rather than an organization, so there is no organizational backing to offset the single-maintainer context.
The package is less than one day old, with three releases in hours, so there is not enough history to demonstrate sustained maintenance or maturity.
There are no commits or active maintainers recorded over the last three months, but the repository is newly created, so this is more a lack of history than evidence of abandonment.
The repository name does not exactly match the package name, and no README mention was available. This creates some uncertainty that the linked repository is the package's intended source, although a subpackage naming difference alone is ordinary.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
niangpro/core Version self.version | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.