The MIT license, consumer README, and repository tests make adoption transparent. No install scripts or deprecation notice reduce routine dependency risk, but the project has limited history and concentrated maintenance.
68%
Total Score
83
83
75
The package is only 37 days old with four releases, showing active initial development but limited evidence of long-term maintenance and maturity.
All 13 recent commits came from one contributor, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity but does not remove the current single-contributor concern.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Version 0.7.3 is not marked prerelease, but the package remains below a stable 1.0 major release, so compatibility maturity is not yet established.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both of its two action references are unpinned, weakening build reproducibility and supply-chain controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gpio/contracts Version ^0.7.0 | — | — |
fabricate/console Version ^0.7.0 | — | — |
fabricate/sketches Version ^0.7.0 | — | — |
fabricate/contracts Version ^0.7.0 | — | — |
waveforms/contracts Version ^0.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.