The package includes tests, a substantial README, recent releases, and only two runtime dependencies. Its single-contributor maintenance base, absent security policy, repository naming mismatch, and license mismatch warrant caution before adoption.
65%
Total Score
50
100
75
75
The manifest declares MIT and license files are present, so the release is licensed. However, the artifact also contains detected Apache-2.0 text not covered by the declaration, creating a licensing clarity concern.
One contributor made all commits in the last three months, giving the project a single-person maintenance dependency. The repository owner is an individual rather than an organization, so there is no provided backing evidence to compensate for this concentration.
Only two commits were made in the last three months. That shows some recent activity, but the volume is low for a security-sensitive access-control module.
The repository name does not match the package name, and the README was not confirmed to mention the package. A naming mismatch can be normal for related repositories, but the available evidence does not establish that this repository clearly belongs to the package.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counters provide little independent evidence of broad review or adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
weline/framework Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.