MNG Kargo carrier for Omniship shipping library
66%
Total Score
caution
Usable with caveats: healthy packaging and recent releases, but maintenance is concentrated in one contributor.
The registry namespace and repository are owned by the same individual user, which supports clear ownership but provides no organizational maintenance redundancy.
One contributor accounts for all commits in the last three months, leaving no demonstrated maintenance redundancy. The repository is user-owned rather than organization-owned, so there is no provided backing signal to offset that concentration.
Only one commit was recorded in the last three months, and one active maintainer produced it. Recent publishing activity helps, but source maintenance appears limited.
Composer is used as a build tool, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This lowers project transparency but does not by itself make the release unfit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
tcgunel/omniship-common Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.