The repository includes tests, release notes, and organization backing, with no install scripts or deprecation. Workflow references are not pinned and the project lacks a security policy, while recent work is concentrated in one contributor.
76%
Total Score
67
93
67
All recent commits came from one contributor. Organization backing partly reduces handoff risk, but the observed recent activity still shows limited contributor breadth.
There were two commits in the last three months, so development is still occurring, but the activity level is modest.
The project uses Composer and Make for builds, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy. This does not show a maintenance failure by itself, but it weakens the project's documented process for handling security reports.
The workflow was fully analyzed, uses read-only permissions, and has no detected high-confidence audit findings. However, all 9 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jbzoo/data Version ^8.0 | — | — |
jbzoo/event Version ^8.0 | — | — |
jbzoo/utils Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.