b13/aim 0.5.0 appears usable and actively maintained, with six releases over 148 days, a repository pushed on the assessment date, 28 commits from four active maintainers in the last three months, and recent issue and pull-request resolution. The package is well documented and scaffolded with tests and a changelog, has an explicit GPL-2.0-or-later license, no install-time lifecycle scripts, and is backed by an organization-owned repository that matches the package. The main concerns are that the README explicitly identifies the API as alpha and potentially unstable before 1.0, commit activity is concentrated in one contributor, and the repository lacks a security policy, security-scanning tools, and top-level workflow permission declarations. These are meaningful transparency and operational-hygiene gaps, but there is no evidence of deprecation, archival, abandoned development, or repository/package mismatch.
78%
Total Score
80
100
88
80
Only one registry account has publish access, which is a publishing continuity concern, although the repository's organization backing and observed contributor activity provide some compensation.
The top contributor made 23 of 28 commits, or about 82%, which concentrates maintenance risk; four active contributors and organization ownership partly compensate but do not remove the concern.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-process gap for a package that handles provider credentials and AI requests.
The repository has no security policy, reducing the transparency of vulnerability reporting and response expectations.
Neither workflow declares top-level token permissions. Although no workflow has top-level write permissions, the absence of explicit least-privilege declarations is a workflow-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12.4 || ^13.4 || ^14.0 | — | — |
typo3/cms-backend Version ^12.4 || ^13.4 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.