The MIT license, stable release, and active recent publishing provide a clear foundation. A single active contributor, no tests or security policy, and broad unpinned workflow permissions leave meaningful maintenance and build-hygiene concerns.
68%
Total Score
83
100
94
75
One contributor made all 12 recent commits, creating a genuine continuity risk; organization ownership partly compensates because maintenance can potentially be handed off.
Composer is used for builds, but no security scanning tool was detected, leaving a modest gap in repository security hygiene.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.
The only workflow was fully analyzed with no high-confidence audit findings or untrusted-code sinks. However, it grants top-level write permissions and both action references are unpinned, creating moderate build-reproducibility and credential-scope concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rimba/foundation Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.