Usable with caveats: it is actively released, tested, licensed, and backed by an organization, but it is still young and all recent commits come from one contributor. Missing security policy and undeclared workflow token permissions add transparency and CI-hygiene concerns.
74%
Total Score
70
100
83
80
Only one registry account has publishing access, which is a concentration concern, though the organization-backed repository provides some compensating ownership context.
All three recent commits came from one contributor, creating concentration risk; organization ownership partly mitigates the risk because maintenance can potentially be handed off.
Three commits were made in the last 3 months by one active maintainer, demonstrating recent work but a modest maintenance cadence.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not determine health for a young package.
Composer build tooling is present, but no security-scanning tool was detected, leaving a security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
papi-ai/papi-core Version ^0.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.