Comprehensive tests, release notes, and security scanning support adoption. A single active contributor, absent security policy, and unpinned workflow actions leave maintenance and build-hygiene concerns.
68%
Total Score
67
100
94
67
The package has 16 releases over about 5 years, but none in the last 12 months. This is a meaningful maintenance concern, although the repository was pushed recently and the assessed release has documented notes.
One contributor made all commits in the last 3 months. Organization backing provides some handoff capacity, but current observed activity is still concentrated in one person.
Only one commit was recorded in the last 3 months, showing some recent activity but a slow current maintenance pace. This partially offsets the absence of recent registry releases without removing the concern.
No repository security policy was found. For a library handling LTI services, this reduces transparency around vulnerability reporting and response.
Both workflows were analyzed successfully with no untrusted checkouts, script injection, or high-severity findings, and neither uses broad top-level write permissions. However, all 6 of 6 action references are unpinned, leaving avoidable build reproducibility and action-supply-chain risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
nesbot/carbon Version ^2.72 || ^3.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
oat-sa/lib-lti1p3-core Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.