The release is well documented, licensed, tested, and recently published. Maintenance is concentrated in one contributor, while the repository has no security policy or scanning.
68%
Total Score
50
100
89
75
One contributor made all two recent commits, leaving maintenance highly concentrated and creating continuity risk despite the recent release.
Only two commits were made in the last three months, which shows some recent activity but indicates a relatively thin maintenance cadence.
The repository has one star and no forks or watchers, offering little community evidence to complement the maintainer's activity.
Composer build tooling is present, but no security-scanning tool was detected, leaving security-quality checks less transparent.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pinga/db Version ^0.1.3 | — | — |
pinga/base64 Version ^0.1 | — | — |
pinga/cookie Version ^0.2 | — | — |
pinga/session Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.