The Apache-2.0 license, readme, tests, release notes, and focused dependencies improve transparency. Actions use read-only permissions, but all three references are unpinned and no security scanner or policy is present.
67%
Total Score
83
100
75
50
The package is only 50 days old, with five releases and a median interval of about one day. That shows active publishing but provides limited evidence of long-term stability.
All 16 recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some handoff capacity but does not remove the current concentration.
Composer is used for builds, but no security scanning tool is configured. This is a maintenance and detection gap, though not evidence of unsafe behavior by itself.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
The current v0.2.1 release is not prerelease, but the package remains below a stable major version, so its API and behavior may still change substantially.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pushinbr/pam-native Version ^0.8 || ^0.9 || ^0.10 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.