Usable with caveats: the release is well-scaffolded, licensed, reproducibly packaged, and backed by an active-looking organization repository, but it has no established release history and no recorded recent commit activity. Treat it as a new dependency and verify ongoing maintenance before adopting it broadly.
65%
Total Score
75
100
88
90
This is the first recorded release and the package is only 0 days old, so there is no demonstrated release track record or cadence yet.
No commits and no active maintainers were recorded in the last 3 months. The very recent repository push and one-day-old package limit how much this indicates abandonment, but maintenance capacity is not yet demonstrated.
The repository uses Make and Composer, but no security scanning tools were detected. The build tooling is positive, while the missing scanning is a modest transparency gap.
No repository security policy was found, leaving vulnerability-reporting expectations undocumented for a package intended for application integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version 1.82.0 | — | — |
google/protobuf Version 4.33.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.