AI Analysis
The package has low risks in terms of network, shell, obfuscation, and credential handling. However, the metadata risk score is high due to the lack of maintainer information and minimal repository activity, raising concerns about its origin and maintenance.
- High metadata risk due to missing maintainer information and low repository activity
- Overall low risk in other categories but cannot rule out potential supply-chain issues
Per-check LLM notes
- Network: No network calls detected, which is normal if the package does not require internet connectivity.
- Shell: No shell execution patterns detected, indicating no immediate signs of executing system commands.
- Obfuscation: No obfuscation patterns detected, indicating low risk.
- Credentials: No credential harvesting patterns detected, indicating low risk.
- Metadata: The package shows signs of being potentially suspicious due to lack of maintainer information and minimal repository activity.
Package Quality Overall: Medium (5.8/10)
Test suite present — 3 test file(s) found
Test runner config found: pyproject.toml3 test file(s) detected (e.g. helpers.py)
Some documentation present
Detailed PyPI description (2641 chars)
No contributing guide or governance files found
No CONTRIBUTING, CODE_OF_CONDUCT, or governance files found
Partial type annotation coverage
35 type-annotated function signatures detected in source
Active multi-contributor project
3 unique contributor(s) across 36 commits in klconsultancy/aiophoenixcontactcharxSmall but multi-author team (3–4 contributors)
Heuristic Checks
No suspicious network call patterns found
No obfuscation patterns detected
No shell execution patterns detected
No credential harvesting patterns detected
No typosquatting candidates detected
No author email provided
All external links appear legitimate
Git history flags: Repository has zero stars and zero forks
Repository has zero stars and zero forks
2 maintainer concern(s) found
Author name is missing or very shortAuthor "" appears to have only 1 package on PyPI (new or inactive account)
No known vulnerabilities found in OSV database.
AI App Starter Prompt
Build a simple Python application using the aiophoenixcontactcharx package to demonstrate its core features.