Its documentation, tests, and security policy are in place. The project is still very young, relies on one active contributor, and uses four unpinned workflow actions, so maintenance continuity deserves attention.
68%
Total Score
50
100
94
100
Only one registry account can publish the package. That is a limited publishing base, though the linked repository is also owned by the same individual rather than an organization.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to offset the concentrated maintainer base.
The package is only 51 days old with three releases and a median interval of about 9 days, showing active early development but limited history for judging durability.
All five recent commits came from one contributor, leaving no demonstrated handoff capacity if that maintainer becomes unavailable.
Five commits from one active maintainer in the last three months show recent work, but the volume is still modest for a package with a broad security-focused scope.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.