psycopg2 2.9.13 appears to be a healthy, mature dependency: it has a long release history, a current stable release, no registry deprecation, an active non-archived organization-owned repository, recent commits and pull-request activity, documented source structure, tests and changelog in the repository, and established build and dependency-security tooling. The main reservations are modest recent commit volume, concentration of recent commits in two contributors, no repository security policy, workflows without explicit top-level permissions, and no packaged type declarations; these are hygiene or ergonomics concerns rather than evidence of abandonment, and the organization backing and repository activity partly compensate for the contributor concentration.
88%
Total Score
88
100
80
There were 4 commits from 2 active maintainers in the last 3 months. Activity is present but relatively light, so it provides less maintenance assurance than a highly active project.
No security policy was found in the repository. This is a transparency and vulnerability-reporting gap, though it is mitigated somewhat by the presence of Dependabot scanning.
All 4 workflows lack top-level permissions declarations, although none declares top-level write access. Explicit least-privilege declarations would improve CI hygiene, so this is a moderate caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.