Tests, a changelog, two active contributors, and organization backing support continued maintenance. Unpinned workflow actions and missing security policy leave avoidable supply-chain and disclosure gaps.
68%
Total Score
100
100
81
75
The package is only 38 days old and has two releases, both published within hours on the same day. This provides too little history to establish durable maintenance, despite recent activity.
Composer build tooling is present, but no security scanning tool was detected. For a package handling encryption and threat detection, that is a meaningful process gap.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities in a security-focused package.
Version v0.1.1 is not a prerelease, but the 0.x major version indicates an early, potentially changing API. The repository's tests and changelog provide some maturity support.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all four action references are unpinned. That leaves build behavior exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
libxa/framework Version ^0.10.2 || ^0.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.