Tests and release notes improve transparency, while the organization-owned repository provides clear ownership. The release is brand new, has no established commit history or security policy, and all seven workflow actions are unpinned.
67%
Total Score
75
100
83
50
This is the first release and the package is 0 days old, so there is no observed release track record yet. That is an adoption risk, although it is expected for a newly published package.
The repository shows zero commits and zero active maintainers over the last three months, leaving maintenance capacity unproven. Because the package was released 0 days ago and has two merged pull requests this month, this is caution rather than abandonment evidence.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap for a package handling storage integrations.
The repository has no security policy. That makes the process for reporting and handling vulnerabilities unclear, though it does not show that the package is unsafe.
Version v0.1.0 is not a stable major release, so its API and behavior may change while the project matures. It is not marked as a prerelease, which partly offsets the concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
naf/framework Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.