milpa/ops v0.3.2 appears usable and well-structured, with a matching repository, Apache-2.0 licensing, tests, changelog, security policy, active release and pull-request activity, and no deprecation or archival indicators. The main reservations are that the package is young at 41 days, remains below a stable major version, and all recent commits come from one contributor; organization backing partly mitigates the bus-factor concern but does not eliminate it. The repository also lacks detected security-scanning tooling and several workflows grant top-level write permissions, which warrants review before adoption. Overall, it is a promising actively developed dependency rather than a mature, low-risk one.
78%
Total Score
90
78
90
Seven releases in 41 days, with a median interval of about 2.5 days and a release as recently as the assessment date, show strong current activity; the short history still limits maturity evidence.
One contributor made all eight recent commits, creating a genuine continuity risk; organization ownership partially compensates because maintenance can potentially be handed off.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity is not decisive and the observed development activity is more relevant.
Composer build tooling is present, but no security-scanning tool was detected. The repository's SECURITY.md and CI workflows provide some compensating hygiene, but not equivalent automated scanning.
All workflows declare permissions, but three grant top-level write permissions while only one is read-only; this expands CI credential scope and merits review, despite the absence of other dangerous workflow patterns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.