async-aws/kinesis 3.6.0 appears healthy and suitable for dependency use. It has a stable release, recent publication, a non-deprecated registry status, an active and unarchived organization-backed repository, recent commits from two maintainers, a matching and clearly identified source repository, a license file, tests in the repository, and no install-time lifecycle scripts or dangerous workflow patterns. The main reservations are limited repository popularity, no declared security policy or security-scanning tooling, and workflows without top-level token permissions; these are transparency and hardening gaps rather than evidence of abandonment. Some signals were not collected, so the assessment is strong but not fully comprehensive.
87%
Total Score
100
100
89
80
The repository has only 2 stars and no forks, indicating limited public adoption or visibility, but popularity is supporting evidence and does not outweigh the observed maintenance and organization backing.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected; the build process is structured while security automation coverage is a gap.
No security policy was found in the repository, which reduces vulnerability-reporting transparency and is a genuine but non-critical hygiene gap.
Both workflows lack top-level token-permission declarations. No top-level write permissions were observed, but explicit least-privilege declarations would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
async-aws/core Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.