Documentation and testing are solid, with organization backing and security scanning in place. The limited recent activity and workflow pinning leave more maintenance and build-integrity risk than a fully healthy dependency.
67%
Total Score
67
94
67
The package has 8 releases since October 2020, but none in the last 12 months; the latest registry release is over a year old. This is a meaningful maintenance concern despite the package's established history.
All recent commits came from one contributor, giving the project a high short-term bus-factor risk. Organization ownership provides some handoff capacity, but no second recent contributor is shown.
Only 1 commit from 1 active maintainer was recorded in the last 3 months. That is weak current activity and raises abandonment risk, even though the repository is not archived.
The repository has no security policy. For a library handling LTI security workflows, this is a transparency and response-process gap.
Both workflows were analyzed without high-confidence findings or untrusted triggers, but all 6 action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain controls, so this is a hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
oat-sa/lib-lti1p3-core Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.