The package includes tests, clear installation guidance, a matching repository, and a security policy. Its automation lacks dependency pinning and security scanning, while the single-release history leaves maintenance capacity unproven.
61%
Total Score
50
50
81
100
Eleven runtime dependencies create a relatively broad dependency surface for a new package, increasing the amount of upstream maintenance it relies on, though no dependency is shown to be abandoned here.
The package and repository are associated with a user-owned project rather than an organization-backed repository; this does not show abandonment, but it provides limited evidence of maintenance capacity.
This is a young package with one release in 105 days and no established release cadence, so ongoing maintenance is not yet demonstrated.
There were no commits and no active maintainers in the last three months, despite the repository being only 105 days old; this leaves ongoing maintenance unproven.
The repository has zero stars, forks, and watchers. This is only supporting evidence, but it provides no external adoption signal to offset the limited maintenance history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
switon/di Version ^1.0 | — | — |
switon/log Version ^1.0 | — | — |
switon/core Version ^1.0 | — | — |
switon/http Version ^1.0 | — | — |
switon/event Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.