The small source repository has limited recent activity and all recent commits come from one contributor. MIT licensing, organization backing, frequent releases, and no install-time scripts provide useful support for adoption.
73%
Total Score
67
100
75
One contributor made all commits in the last 3 months, giving the repository a complete single-contributor concentration. Organization backing helps with handoff potential, but no second active contributor is shown.
Only 2 commits were recorded in the last 3 months, so direct source activity is modest despite the recent release cadence. This leaves some maintenance-capacity concern.
The repository has no security policy. For a small library this is a transparency gap rather than an immediate adoption blocker, but it weakens the process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rekalogika/file Version ^2.5 | — | — |
rekalogika/file-contracts Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.