Clear licensing, release notes, tests, and organization backing support dependable use. Limited recent participation, absent security policy, and unpinned workflow actions leave modest maintenance and build-integrity risk.
77%
Total Score
67
100
50
All 2 recent commits came from one contributor. Organization backing provides some handoff capacity, but no second recent contributor is shown to reduce concentration risk.
The repository recorded 2 commits in the last 3 months, showing some recent maintenance, though the volume is modest.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, not evidence of unsafe code.
Both workflows were fully analyzed with no detected sinks or audit findings, but all 4 action references are unpinned. That leaves avoidable workflow supply-chain exposure despite the otherwise clean audit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
async-aws/core Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.