MIT licensing, included tests, and release notes provide useful transparency. The organization-backed repository was pushed with this release, but the missing security policy and unpinned workflow actions reduce confidence in long-term maintenance and build hygiene.
68%
Total Score
100
100
81
75
The package is only 1 day old with two releases, so its release cadence and maintenance record are not yet established.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, so consumers lack documented guidance for reporting vulnerabilities or understanding the project's security process.
Version v0.1.1 is not a stable major release, indicating an early API and compatibility stage even though it is not marked prerelease.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous audit findings, but both of its two action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
naf/framework Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.