The MIT license, repository tests, and release notes improve transparency. There is no security policy, while the release workflow grants broad token access and uses nine unpinned actions.
70%
Total Score
67
100
88
75
The repository is owned by an individual user rather than an organization, so the single-contributor maintenance concentration is not visibly offset by organizational backing.
The package is young at 144 days and has 21 releases, including recent activity, which shows momentum but not long-term durability; the extremely short median interval suggests concentrated burst publishing.
All 15 recent commits came from one contributor, so maintenance depends entirely on a single person and has limited handoff resilience.
Composer is used for builds, but no security-scanning tools were detected; the missing scanning layer is a modest transparency and maintenance concern.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hashids/hashids Version ^4.1 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.