Healthy and actively maintained, with frequent releases, current repository activity, and a tested, documented codebase. The main caveat is that recent commits are concentrated in one contributor and the repository lacks a security policy and explicit workflow token permissions.
84%
Total Score
88
100
94
80
One contributor made about 92% of the 26 recent commits, which creates concentration risk. The two additional active contributors and organization ownership partly compensate, so this is a caution rather than a severe abandonment concern.
The repository uses Composer for builds, but no security-scanning tool was detected. The missing scanner is a modest transparency gap because other maintenance and CI evidence is present.
No security policy is present in the repository. This weakens vulnerability-reporting transparency, although it is partly offset by the active repository and otherwise controlled workflow profile.
The one workflow does not declare top-level token permissions. No write permissions were detected, but explicit least-privilege settings would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
karmabunny/kb Version ^5.68 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.