Healthy and actively developed, with strong documentation, tests, and frequent releases. Dependence is somewhat concentrated in one maintainer and the repository lacks security-policy and scanning coverage, so consider those operational risks before adopting it broadly.
78%
Total Score
75
100
94
75
The registry namespace and repository are owned by the same individual, so the package has clear ownership but no organizational backing to provide maintenance redundancy.
All 31 commits in the last three months came from one contributor, so maintenance depends heavily on a single individual and could be disrupted if they become unavailable.
The project uses Make and Composer for builds, but no security-scanning tools were detected. For a package centered on sandboxing untrusted code, that missing automated security coverage is a meaningful transparency gap.
The repository has no security policy. That leaves vulnerability reporting and the project's security-response process unclear, which matters for a sandboxing-focused package.
One workflow lacks top-level permissions and the release workflow grants write permissions. Although no dangerous workflow patterns were detected, broader write access than necessary increases CI governance risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.