The package includes tests, release notes, documentation, and an actively contributing organization-backed project. Its short history, early version line, absent security scanning, and unpinned workflow actions leave meaningful maturity and build-integrity concerns.
70%
Total Score
100
50
79
67
The package declares 25 runtime dependencies, including many NAF framework components and extensions. This is substantial coupling for a v0.1 package and increases upgrade and compatibility risk, though the dependencies fit its role as a full application plugin.
The package is only 1 day old with 4 releases, and the median release interval is about 1 hour 27 minutes. This shows active initial development but provides little evidence of long-term maintenance stability.
Composer build tooling is present, but no security-scanning tools were detected. For a package with application, database, authentication, and storage functionality, that is a modest supply-chain hygiene gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the active organization-backed project provides some compensating maintenance capacity.
Version v0.1.3 is not a stable-major release, so its API and behavior may still change. It is not marked as a prerelease, which partly reduces the concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
naf/cli Version ^0.2.2 | — | — |
naf/mcp Version ^0.2.1 | — | — |
naf/orm Version ^0.2.2 | — | — |
naf/auth Version ^0.2.1 | — | — |
naf/form Version ^0.2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.