Security scanning, tests, and a clear MIT license provide useful safeguards. The one-person maintenance base and repository mismatch make this release harder to trust long term.
55%
Total Score
50
88
83
The linked repository is named php-gluo rather than byjg/rest-reference-architecture and its README does not mention this package. That mismatch raises concern that the repository may not be the package's actual source.
The repository is owned by a user account rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
One contributor made 100% of the 40 recent commits. This creates a significant continuity risk because no second active contributor is evidenced.
The repository recorded 40 commits in the last 3 months, showing active work, but all activity came from one maintainer, limiting demonstrated maintenance breadth.
All three workflows were analyzed, but all 14 action references are unpinned and one workflow grants top-level write access. The only reported cache-poisoning issue is low confidence, so this is workflow hygiene rather than a severe finding.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
byjg/config Version ^6.0 | — | — |
byjg/shortid Version ^6.0 | — | — |
byjg/authuser Version ^6.0 | — | — |
byjg/jinja-php Version ^6.0 | — | — |
byjg/micro-orm Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.