The package is well documented, tested, licensed, and recently released. Its small maintainer and contributor base, plus unpinned CI actions, reduce independent assurance.
76%
Total Score
50
100
89
88
The registry and repository are owned by the same individual account. This provides consistent ownership, but no organization backing is shown to offset the concentrated maintainer base.
One contributor made all commits in the last three months, giving the project a complete short-term contributor concentration. For this individually owned project, that leaves little redundancy if the maintainer stops.
The repository recorded one commit in the last three months from one active maintainer. Recent activity is present but very light, so maintenance capacity is limited.
The repository has one star, no forks, and one watcher. This is limited community adoption and therefore offers little independent validation, although popularity alone is not a health verdict.
Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a modest transparency and assurance gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
andrewgjohnson/agjgd Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.