The project is young, with only 80 days of release history, and all six recent commits came from one contributor. Its MIT licensing, active unarchived repository, stable version, and organization backing provide useful reassurance, but documentation and security-process coverage are thin.
68%
Total Score
83
86
75
The artifact has no README, tests, or changelog, but tests and changelogs are normally repository concerns and their absence is not a packaging defect here. The missing README modestly reduces consumer transparency for a library.
All six recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some capacity to hand maintenance off, but no second active contributor is shown.
Composer is used for builds, but no security-scanning tools were detected. This is a modest process gap rather than evidence of unsafe code.
The repository has no security policy, reducing transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
plover/nest Version ^1.1 | — | — |
plover/toolkit Version ^1.0 | — | — |
plover/nest-config Version ^1.0 | — | — |
plover/nest-router Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.