Tests, release notes, and security tooling make the project easier to evaluate. Organization ownership helps, but the long release gap and fully unpinned workflow actions warrant checking before adoption.
67%
Total Score
75
100
94
50
The package has four releases since October 2021, but none in the last 12 months and the latest release was over two years ago, indicating a real maintenance gap.
The repository recorded no commits and no active maintainers in the last three months. This is partly offset by a non-archived repository with a more recent recorded push, but current activity remains quiet.
The repository has no security policy. This reduces transparency for reporting and handling vulnerabilities, although its security scanning tools provide some compensating process.
Both workflows were fully analyzed with no untrusted checkouts, injection findings, or write-wide permissions, but all five referenced actions are unpinned. That leaves avoidable build-supply-chain drift.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
oat-sa/lib-lti1p3-core Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.