It has a clear MIT license, a substantial README, a repository security policy, and read-only workflow permissions. Automated security tooling is absent, and neither of the two workflow actions is pinned.
61%
Total Score
50
100
81
100
The package includes a 5,352-character README, and the repository has a changelog. The absence of tests in the published artifact is normal packaging practice, while the repository's lack of tests is a modest maturity concern for security-sensitive SDK code.
The repository is owned by an individual user rather than an organization, so there is no visible organizational handoff capacity to offset the narrow maintainer base.
The package is only 18 days old and has one release, so there is little history to establish maintenance reliability or release maturity.
One contributor made 100% of the one recorded commit, leaving maintenance fully concentrated in a single person.
Only one commit was recorded across the last three months, indicating very limited observed maintenance activity for a package that handles identity and credential verification.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
endroid/qr-code Version ^5.1 | — | — |
web-token/jwt-library Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.