Documentation, tests, release notes, and an ISC license are present, with no install-time scripts. The organization-backed repository has security scanning, but all five workflow actions are unpinned and the repository does not identify this package.
66%
Total Score
67
93
75
The repository recorded 0 commits and 0 active maintainers in the last 3 months. That is a meaningful maintenance concern, even though the registry shows recent releases.
There were no new or closed issues or pull requests in the last month, while 2 pull requests remain open. Together with zero recent commits, this suggests limited current project activity.
The repository name does not match the package name and its README does not mention this package. That leaves some uncertainty about package-to-source ownership, despite the organization-backed repository.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the separate repository tooling signal shows Aikido security scanning.
All 5 analyzed action references are unpinned, so workflow dependencies can change without a reviewed version update. The audit found no untrusted checkouts, script injection, excessive top-level write permissions, or other reported findings.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10210 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. statsig/statsigsdk is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor in versions 3.2.0 - 3.3.0. | 3.2.0 - 3.3.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
ua-parser/uap-php Version 3.9.* | — | — |
statsig/ip3country Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.