The package is small and clearly documented, with tests in the published artifact and one runtime dependency. Its single maintainer and more than two years without a release make long-term support uncertain; the repository could not be found for verification.
45%
Total Score
50
100
70
100
The package has had no release in more than two years, despite four releases overall. That long period without a new release raises abandonment risk for a dependency.
Only one registry maintainer is listed, leaving limited visible continuity if that person stops maintaining the package. No activity signal is provided to show that this narrow ownership is compensated.
Version 0.0.4 is not a stable major release, so the public contracts may still change incompatibly. No prerelease labeling partly reduces the concern, but the very early version remains a maturity limitation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vitrin-infrastructure/types Version ^0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.