The package includes a clear README, changelog, repository tests, and a matching MIT license. Its workflows have no detected dangerous findings, but all four action references are unpinned and no security policy or scanning tool was found.
78%
Total Score
67
100
92
50
One contributor made all commits in the last 3 months, creating a concentrated recent maintenance path; organizational backing reduces handoff risk but does not remove the concentration.
Only one commit was recorded in the last 3 months, showing limited recent activity, although the release history indicates the package is still being delivered.
The repository uses Make and Composer build tooling, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
No repository security policy was found, reducing the project's documented process for receiving and handling vulnerability reports.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 4 action references are unpinned, which is a workflow supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
async-aws/core Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.