Clear documentation, tests, release notes, and licensing improve confidence. The small dependency footprint and read-only workflow permissions also reduce practical exposure, but this remains an early package.
67%
Total Score
50
75
100
The package has four releases, all clustered within roughly 20 minutes, with no later release across the following 139 days. That shows initial activity but not an established release cadence.
The repository recorded zero commits and zero active maintainers during the last three months, despite the latest release having been published about 139 days earlier. This is the strongest abandonment concern in the assessment.
Composer build tooling is present, but no security scanning tool was detected. This is a hygiene gap that matters for a library handling authentication-related integrations, though it is not evidence of unsafe code by itself.
v0.2.2 is a stable, non-prerelease version, but the package has not reached a stable major version. That is a modest maturity concern rather than a severe adoption blocker.
All three workflows were analyzed successfully and use read-only permissions, with no injection or high-confidence audit findings. However, all eight analyzed action references are unpinned, leaving builds exposed to mutable upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
gimucco/atproto-php Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.