The workflows use read-only job permissions and completed their audit without dangerous findings. All three actions are unpinned, and the repository has no security policy or scanning tools.
68%
Total Score
83
81
75
The package is only 49 days old with four releases, so its maintenance record is still short despite a brisk release cadence.
All 14 recent commits came from one contributor, creating a concentrated maintenance risk; organization ownership provides some capacity for handoff but does not remove the gap.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest verification gap.
The repository has no security policy, which weakens vulnerability-reporting transparency for a package handling native playback and DRM integrations.
Version v0.3.1 is not a prerelease, but the package remains below major version 1, indicating an earlier-stage API and project.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pushinbr/pam-native Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.