Clear documentation, tests, licensing, and organization backing support adoption. The lack of commits for three months, absent security policy, and four unpinned workflow actions reduce confidence in ongoing maintenance and build hygiene.
68%
Total Score
75
100
88
83
The package has existed since October 2020 and had two releases in the last 12 months, but the latest release was about seven months ago, indicating a moderate rather than active cadence.
There were no commits and no active maintainers in the three months measured. The recent repository push and registry releases partly offset this, but the short-term activity gap remains a maintenance concern.
The repository uses Composer and Make for builds, but no security scanning tools were detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, which makes vulnerability reporting and disclosure expectations less clear for consumers.
Both workflows were analyzed successfully with no dangerous audit findings or untrusted checkouts, but all four action references are unpinned, reducing build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
async-aws/core Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.