This is a healthy, mature release with more than six years of history, 42 releases, seven releases in the last 12 months, and a recent release cadence. The linked organization-owned repository is active, unarchived, correctly associated with the package, and has recent commits from three contributors with no severe workflow hazards. The package is licensed, includes a changelog, and has repository tests, although the artifact omits tests and the repository lacks a security policy, automated security-scanning tools, and explicit top-level workflow permissions. These are meaningful hygiene gaps but do not outweigh the strong maintenance, backing, release, and repository evidence.
88%
Total Score
88
100
94
80
There were no new or closed issues or pull requests in the last month, which provides little evidence of current issue engagement; the neutral result is partly offset by recent commits and releases.
The project uses Make and Composer, showing build tooling, but no security-scanning tools were detected, leaving a security-process hygiene gap.
No repository security policy was found, reducing vulnerability-reporting transparency and making this a genuine but limited governance gap.
Neither analyzed workflow declares top-level permissions, and neither declares read-only permissions; this weakens explicit CI token hardening even though no write permissions were detected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
async-aws/core Version ^1.22 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.