Documentation and packaging are adequate for this PHP FFI adapter, with a recent release and an active organization-owned repository. Maintenance activity is sparse, security-policy coverage is absent, and both workflow action references are unpinned.
70%
Total Score
83
50
88
75
Nine runtime dependencies create a relatively broad dependency chain for an adapter, including native FFI and platform libraries. That complexity is consistent with the package's stated role but increases upgrade and environment-management burden.
The package is over two years old with seven releases, but only one release arrived in the last 12 months. The recent 1.1.0 release shows the project is not abandoned, though its cadence is currently thin.
Only one commit was recorded in the last three months, from one active maintainer. The recent release offsets this somewhat, but ongoing maintenance activity is sparse.
Composer is used for builds, but no security-scanning tool was detected. The missing scanner is a transparency and hygiene gap, not evidence of unsafe code by itself.
The repository has no security policy. For a package that integrates native libraries through FFI, this leaves vulnerability-reporting expectations less clear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rindow/rindow-matlib-ffi Version ^1.0 | — | — |
rindow/rindow-opencl-ffi Version ^1.0 | — | — |
rindow/rindow-clblast-ffi Version ^1.0.5 | — | — |
rindow/rindow-math-matrix Version ^2.2 | — | — |
rindow/rindow-openblas-ffi Version ^1.0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.