rimba/lms v1.4.6 appears usable and actively maintained, with 27 releases over 41 days, a stable non-prerelease version, recent repository activity, organization backing, and no deprecation or archival indicators. However, it is still a young package, all 25 recent commits come from one contributor, the artifact and repository contain no tests or changelog, the repository has no security scanning or security policy, and its release workflow grants top-level write permissions. These factors make it a reasonable dependency with meaningful maintenance and supply-chain hygiene concerns that should be monitored.
68%
Total Score
90
100
78
80
The package and repository have no README, tests, or changelog. GitHub Releases provide some release communication, but the absence of tests and user-facing documentation remains a genuine transparency and maintenance gap.
The package is young at 41 days old but has 27 releases, with a median interval of about 20 hours. This demonstrates active publishing, although the short history limits evidence of long-term maintenance.
One contributor made all 25 commits in the last 3 months, creating a genuine continuity risk. Organization backing partially compensates because maintenance can potentially be handed off, but no second active contributor is evidenced.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counters provide no external adoption signal for this young package.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning reduces repository hygiene and supply-chain transparency, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rimba/dms Version ^1.3 | — | — |
rimba/foundation Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.