The license, README, tests, read-only workflow permissions, and security scanning improve day-to-day confidence. Organization backing and active recent work help, but the release is still early and lacks a published security policy.
62%
Total Score
83
100
88
50
This is a young package, only 56 days old, with 22 releases published on the same day and a median interval of 0 days. That rapid initial burst provides limited evidence of a settled release process.
One contributor made all 156 commits in the last 3 months, creating a genuine continuity risk. Organization ownership provides some handoff capacity but does not remove the absence of a second active contributor.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a package that coordinates agents and MCP tools.
Version v0.22.0 is not on a stable major version, which signals a still-evolving API; the release itself is not marked prerelease, partly reducing the concern.
The single analyzed workflow has read-only permissions and no untrusted checkout or script-injection findings, but all 15 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lthn/php Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.