The project is only 47 days old and all 13 recent commits come from one contributor, though organization ownership and recent releases provide some continuity. Workflows use read-only permissions and pass a complete audit, but all three actions are unpinned and no security policy is published.
72%
Total Score
75
100
78
83
The package is only 47 days old with three releases and a median interval of about 12 days, showing active early development but limited long-term maintenance evidence.
One contributor holds 100% of recent commits. Organization ownership provides some handoff capacity, but no second active contributor is evidenced.
Thirteen commits in three months show recent activity, but all were made by one active maintainer, limiting evidence of durable maintenance capacity.
The repository has zero stars, forks, and watchers. For a package only 47 days old this is limited supporting evidence rather than a standalone health failure.
Composer build tooling is present, but no security scanning tools are reported, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pushinbr/pam-native Version ^0.8 || ^0.9 || ^0.10 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.