The package is clearly documented, tested, licensed, and published with release notes. Its short history, single recent contributor, and absent security policy leave maintenance and security practices less proven.
67%
Total Score
67
100
81
88
The package is only 56 days old and has two releases, with a median interval of about 57 days. This is too little history to establish mature release practices, though a release arrived recently.
One contributor made 100% of the three-month commits, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity but does not demonstrate a second active contributor.
Only one commit was recorded in the last three months from one active maintainer. The recent push is positive, but the very thin activity makes ongoing maintenance less proven.
Composer build tooling is present, but no security scanning tools were detected. The package has ordinary build support while repository security checks remain less visible.
The repository has no security policy, so users are given no documented security reporting or response process. This is a transparency gap rather than evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
runapi-ai/core Version ^0.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.