Clear documentation, tests, and release notes support adoption. A single maintainer, missing security policy, and unpinned workflow actions leave limited assurance for long-term use.
68%
Total Score
50
100
94
50
One registry maintainer limits the visible publishing base, although the linked repository is owned by the same individual and recent release activity shows direct ownership.
The package has only three releases over about 16 months, with the latest release about eight months ago; this suggests limited maintenance momentum, though it is not abandonment by itself.
The repository recorded no commits and no active maintainers in the last eight months, which is a meaningful maintenance concern despite the package remaining unreleased rather than archived.
No repository security policy was found, reducing transparency for reporting and handling security issues in a package that manages Tor networking and control connections.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both action references are unpinned, leaving the build exposed to reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
selective/base32 Version ^2.0 | — | — |
symfony/http-client Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.