A library to calculate the time of next retry in apps that need to be fault tolerant and retry failed attempts of doing something.
72%
Total Score
caution
Usable with caveats: active maintenance is offset by single-contributor risk and workflow supply-chain hygiene gaps.
The package runs post-install and post-update scripts, which increases installation complexity and execution surface compared with a package without lifecycle hooks.
Only one account has registry publish access. That is a genuine continuity concern here because the repository is user-owned rather than organization-owned, though repository activity shows the maintainer is currently active.
The source repository is owned by a user account, not an organization, so there is no organizational handoff capacity shown to offset the concentrated maintainer base.
The project has existed for over six years with 11 releases and a release in the last 12 months, but its median interval is about 157 days and only one release occurred recently.
One contributor made 100% of the seven recent commits. With user ownership and no second active contributor shown, maintenance depends heavily on a single person.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.43.0 || ^3.0 | — | — |
thecodingmachine/safe Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.