The MIT license, test suite, security policy, and matching repository provide solid basic transparency. Unpinned workflow actions and no security scanning weaken build hygiene, while the single-person project has limited demonstrated activity so far.
68%
Total Score
50
100
83
83
One registry publishing account is consistent with a small user-owned project, but it provides limited publishing redundancy.
The repository is owned by a user account rather than an organization, and the single registry maintainer therefore represents limited visible project backing.
This is a young package with one release over 106 days and no established release cadence, so its maintenance maturity is not yet demonstrated.
There were zero commits and zero active maintainers in the last three months. With only one release, this leaves ongoing maintenance capacity unproven rather than proving abandonment.
There are no open issues or pull requests and no recent issue or pull-request activity; this is neutral for a young, quiet project but offers little evidence of an active community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
switon/core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.