The library includes a README, repository tests, release notes, and a clean read-only workflow audit. Recent work comes from one contributor, and the workflow uses unpinned actions; organization backing and a current release reduce the concern.
77%
Total Score
83
94
67
Only one commit from one active maintainer was recorded in the last three months, showing a thin recent maintenance cadence despite the current release.
The repository uses Composer and Make, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
No repository security policy was found, which makes vulnerability reporting less transparent, though this is not by itself evidence of unsafe code.
The single workflow was fully analyzed, uses read-only permissions, and has no high-confidence findings, untrusted checkouts, or injection sinks; all 9 action references are unpinned, a minor reproducibility concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jbzoo/data Version ^8.0 | — | — |
jbzoo/utils Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.