Package Health

psycopg2

psycopg2 2.9.13 appears to be a healthy, mature dependency: it has a long release history, a current stable release, no registry deprecation, an active non-archived organization-owned repository, recent commits and pull-request activity, documented source structure, tests and changelog in the repository, and established build and dependency-security tooling. The main reservations are modest recent commit volume, concentration of recent commits in two contributors, no repository security policy, workflows without explicit top-level permissions, and no packaged type declarations; these are hygiene or ergonomics concerns rather than evidence of abandonment, and the organization backing and repository activity partly compensate for the contributor concentration.

Latest 2.9.13PyPIPyPI

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health checks

Repo commit activitycaution

There were 4 commits from 2 active maintainers in the last 3 months. Activity is present but relatively light, so it provides less maintenance assurance than a highly active project.

Security policycaution

No security policy was found in the repository. This is a transparency and vulnerability-reporting gap, though it is mitigated somewhat by the presence of Dependabot scanning.

Token permissionscaution

All 4 workflows lack top-level permissions declarations, although none declares top-level write access. Explicit least-privilege declarations would improve CI hygiene, so this is a moderate caution rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Federico Di Gregorio
Daniele Varrazzo

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
8 days ago
Created
16 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform