The project has one active contributor and no security policy, while its organization backing provides some continuity. Recent releases, tests, a clear README, and a matching repository support dependable maintenance; pin the workflow's unpinned action if adopting it.
78%
Total Score
83
100
94
67
All three recent commits came from one contributor, leaving maintenance dependent on a single person. Organization ownership provides some handoff capacity but does not remove the concentration risk.
Composer is used for builds, but no security-scanning tool was detected, leaving automated security hygiene less visible.
The repository has no security policy, which weakens the documented process for reporting and handling vulnerabilities.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. Its only action reference is unpinned, which is a modest reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nostriphant/nip-44 Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.