The README and changelog make the library easier to understand and maintain, and its repository is active in name and ownership. Documentation of security practices is missing, and the license files do not match the MIT declaration.
61%
Total Score
75
100
86
83
The manifest declares MIT, but the artifact license file is detected as Apache-2.0; although license files are present, this mismatch needs clarification before adoption.
The package has four releases, all within the last 12 months, but the latest release was about nine months ago, suggesting maintenance may have slowed.
The repository recorded no commits and no active maintainers in the last three months, which is a meaningful sign of reduced current maintenance.
The repository has no security policy, leaving reporting and response expectations undocumented; this is a transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
on1kel/oas-core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.