Usable with caveats: the release is clearly packaged, licensed, and backed by an organization with safe workflow permissions. However, it is brand new with no observed commit history, and the repository has no security policy or scanning evidence.
68%
Total Score
75
100
88
90
This is the first recorded release, published 0 days ago, so there is no release track record yet. That limits confidence in long-term maintenance rather than showing abandonment.
No commits or active maintainers were observed in the last 3 months. Because the repository and release are both newly observed, this is primarily an unproven maintenance risk rather than evidence of a collapsed project.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning evidence is a modest transparency gap for a dependency.
No repository security policy was found. That leaves vulnerability-reporting and response practices unclear, although it is not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version 1.82.0 | — | — |
google/protobuf Version 4.33.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.