Documentation, tests, release notes, and automated security scanning are in place. The missing security policy and very limited history leave maintenance capacity and long-term reliability unproven.
67%
Total Score
67
100
89
83
The repository is owned by an individual rather than an organization, so the project has a relatively narrow visible backing structure; this matters more because maintenance history is not yet established.
The package is less than one day old and has only three releases, all published within a few hours, so there is not enough history to demonstrate sustained maintenance.
No commits or active maintainers were recorded in the last three months; because the repository was created less than a day ago, this primarily means maintenance capacity is unproven rather than collapsed.
No repository security policy is provided, leaving the process for reporting and handling vulnerabilities unclear for a package that handles messaging and OTP functionality.
Version v0.2.0 is not a stable major release, which signals an immature API and a higher likelihood of breaking changes for adopters.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.