Healthy and suitable to use, with a young project and concentrated maintenance as the main caveats. It has recent releases, tests, release notes, an active unarchived organization repository, and no install-time scripts or dangerous workflow patterns.
82%
Total Score
88
100
88
80
All seven recent commits came from one contributor, creating a real continuity risk. Organization backing partly compensates because maintenance can potentially be handed off internally, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest security-process gap.
The repository has no security policy, which makes vulnerability reporting and disclosure expectations less clear for a package intended to provide security-related IP blocking.
One workflow grants top-level write permissions while another is read-only. The write-enabled automation increases repository-token exposure, although the separate workflow analysis found no dangerous trigger or checkout pattern.
Version 0.2.0 is not marked as a prerelease, but the package remains below 1.0, so its API and behavior may still change more readily than those of a mature stable-major package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flowd/phirewall Version >=0.9 <1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.