The package includes tests, a clear README, a small runtime dependency set, and composer-audit scanning. Its organization backing helps offset the single active contributor, but the project is too new to establish long-term stability.
68%
Total Score
67
100
92
75
The package is less than a day old with five releases and no established long-term release history, so maintenance and stability remain unproven.
All recent commits come from one contributor. The organization-owned repository provides some handoff capacity, so this is a caution rather than a severe risk.
Only one commit was observed in the last three months from one active maintainer; this is consistent with a new project but does not yet demonstrate sustained maintenance.
No repository security policy was found, leaving vulnerability-reporting guidance unclear for a security-sensitive WebAuthn metadata package.
The workflow audit completed cleanly with no untrusted checkouts, script injection, or high-severity findings, and job-level permissions are used. However, all 8 action references are unpinned, weakening build reproducibility and provenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.