The package has clear documentation, an MIT declaration, a matching repository, and organization ownership. Its validation and security processes are still thin, so production adoption should wait for evidence of broader maintenance.
55%
Total Score
67
100
79
75
This is the package's first release, published on the assessment date, so there is no release history demonstrating sustained maintenance.
All recorded recent commits come from one contributor, creating a thin maintenance base. Organization ownership provides some backing, but no second active contributor is shown.
Only one commit from one active maintainer was recorded in the last three months. Because the package is newly published this may reflect its age, but it provides little evidence of ongoing maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected, leaving security-process coverage limited.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations for a package that integrates with GitHub and handles tokens.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
kompo/auth Version >=0.4 | — | — |
condoedge/utils Version * | — | — |
laravel/framework Version >=10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.