Repository tests, release notes, a security policy, and security scanning provide useful transparency. All workflow actions are unpinned, and one-person ownership leaves long-term support less certain.
68%
Total Score
50
100
94
83
A single registry maintainer is consistent with an individual-owned project, but it gives the release a narrow publishing base if that maintainer becomes unavailable.
The package and repository are owned by the same individual account, so the source relationship is clear, but there is no organizational backing shown to broaden maintenance capacity.
Four releases were published within hours on the package's first day, showing active initial delivery but providing no evidence yet of sustained maintenance.
No commits or active maintainers were observed in the last three months. Because the repository is brand new, this mainly means there is not yet enough history to demonstrate durable maintenance.
Both workflows were analyzed successfully and use read-only permissions with no dangerous triggers or audit findings. However, all 10 action references are unpinned, leaving avoidable supply-chain drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
brick/math Version >=0.12 <2.0 | — | — |
tuupola/base58 Version ^2.2 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.