The package includes tests, a changelog, and matching Apache-2.0 licensing. Its focused scope and small dependency set make integration straightforward, but maintenance and package provenance remain concerns.
58%
Total Score
50
100
69
83
The latest release was about 2 years ago, with no releases in the last 12 months. This is meaningful evidence of slowing maintenance, despite seven total releases since the project began.
There were no commits or active maintainers in the last 3 months, reinforcing the release-history concern and leaving little evidence of current maintenance capacity.
The repository name does not match the package name and its README does not mention the package. A mismatch can be normal for subpackages, but without a README reference the package's source provenance is less clear.
The repository has 1 star, 0 forks, and 0 watchers. Popularity is only supporting evidence, but these figures provide little independent evidence of broad community review or adoption.
The project uses Composer, but no security-scanning tool was detected. The build tooling is appropriate; the missing scanner is a minor hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gioni06/gpt3-tokenizer Version v1.2.0 | — | — |
textualization/sentencepiece Version v0.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.