The package includes tests, a changelog, a matching repository, and a clear Apache-2.0 license. One contributor made all 14 recent commits, workflow actions are unpinned, and no security policy or scanning is present; organization backing partly offsets these concerns.
79%
Total Score
88
100
88
75
One contributor made 100% of the 14 recent commits. Organization ownership provides some handoff capacity, but no second active contributor is shown, so maintenance continuity remains a concern.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy. This is a transparency gap, though the package is young and other release and repository evidence shows active development.
Version v0.2.1 is not a stable major release, so its API may still change, although it is not marked as a prerelease and recent releases are consistent.
Both workflows were fully analyzed, use read-only permissions, and have no reported audit findings or untrusted execution sinks. However, all three referenced actions are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pushinbr/pam-native Version ^0.8 || ^0.9 || ^0.10 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.