The package is clearly documented, licensed, and actively released, with no install-time scripts. Its workflow uses unpinned actions and installs an ad hoc package, while maintenance is concentrated in one contributor and no security policy is published.
67%
Total Score
50
100
92
75
The repository is owned by an individual account rather than an organization, so the single-maintainer and single-contributor concentration is not visibly buffered by organizational backing.
The package is only 40 days old but has four releases, including the assessed version, with a median interval of about 11 hours; this shows active initial development but limited long-term evidence.
One contributor made all 9 commits in the last 3 months, leaving no demonstrated handoff capacity if that maintainer becomes unavailable.
The repository recorded 9 commits in the last 3 months, indicating ongoing activity, but all activity comes from one active maintainer.
The repository has no published security policy, which weakens vulnerability-reporting transparency for a package that bundles 11 other runtime packages.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mortezamasumi/fb-sms Version ^5.0 | — | — |
mortezamasumi/fb-auth Version ^5.1.5 | — | — |
mortezamasumi/fb-user Version ^5.0 | — | — |
mortezamasumi/fb-copydb Version ^5.0 | — | — |
mortezamasumi/fb-passwd Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.