The project has regular releases, recent commits from four contributors, tests, and clear licensing. Workflow credentials are broader than needed, every action reference is unpinned, and the repository does not identify this package in its README.
78%
Total Score
100
100
94
75
The repository name does not match the package name and its README does not mention the package, leaving uncertainty about whether it is the intended source rather than a similarly named or reused project.
No security policy was found, which weakens vulnerability-reporting transparency, though the active repository and Dependabot provide partial compensation.
All three workflows were analyzed, but all 11 action references are unpinned and a high-confidence finding reports a GitHub App token inheriting blanket installation permissions. The pull_request_target workflow has no reported untrusted checkout or script-injection sink, so this is a workflow-hygiene concern rather than a standalone severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.1 | — | — |
pocketmine/nbt Version ^1.0.0 | — | — |
pocketmine/math Version ^0.3.0 || ^0.4.0 || ^1.0.0 | — | — |
pocketmine/color Version ^0.2.0 || ^0.3.0 | — | — |
pocketmine/binaryutils Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.