The package is licensed, documented, tested, and has a matching source repository. Organizational backing and recent releases help, but the short project history leaves limited evidence of long-term maintenance.
70%
Total Score
83
83
50
The package is only 51 days old, but it has published 9 releases in that period, showing active early development rather than abandonment. The short history still limits evidence of sustained maintenance.
One contributor made all 22 recent commits, creating a meaningful continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
No repository security policy was found. This is a transparency gap for a package handling native media and platform integrations, though it is not evidence of unsafe code by itself.
Version v0.3.1 is not a stable major release, so the API may still change. It is not marked as a prerelease, which partly offsets the maturity concern.
Both workflows use read-only permissions and the audit found no high- or medium-confidence findings, but all 3 analyzed actions are unpinned. That leaves avoidable build-reproducibility and action-integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pushinbr/pam-native Version ^0.8 || ^0.9 || ^0.10 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.