The package has clear documentation, tests, frequent releases, and a current GitHub release. Its read-only workflow permissions and organization ownership help, but the project still depends heavily on one active contributor and uses unpinned actions.
78%
Total Score
67
100
94
83
One contributor made 100% of the 133 recent commits. Organization ownership provides some handoff capacity, but no second active contributor is shown, so maintenance continuity remains a concern.
The repository recorded 133 commits in three months, demonstrating strong recent activity. However, all activity came from one maintainer, which limits resilience.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and assurance gap, not evidence of a defect by itself.
The repository has no security policy. For a middleware package involved in policy enforcement, this leaves vulnerability-reporting and response expectations undocumented.
The workflow audit completed successfully, found no injection or high-severity findings, and one workflow uses read-only permissions. However, all 12 action references are unpinned, leaving builds exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
componenta/cqrs Version ^4.0.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
componenta/policy Version ^3.0.0 | — | — |
componenta/identity Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.