LLPhant 1.0.2 appears to be a healthy, actively maintained dependency: it has a mature release history with 137 releases and 20 releases in the last 12 months, the current stable release is not deprecated, and the linked organization-owned repository is active, substantial, and clearly matches the package. Repository tests, CI tooling, Dependabot, TruffleHog, and a clean workflow risk profile provide useful transparency and engineering safeguards. The main concerns are that recent commit activity is modest and concentrated in one contributor, there is no security policy, and workflows do not declare top-level permissions; these are meaningful hygiene gaps but are partly offset by three active contributors, organizational backing, ongoing releases, and security scanning.
86%
Total Score
90
100
100
80
There were 10 commits by three active maintainers in the last three months, showing continued work, but the pace is modest for a fast-moving integration library.
No repository security policy was found, leaving vulnerability-reporting expectations and response procedures undocumented.
All three workflows lack top-level token permissions declarations. Although none declares top-level write access, explicitly restricting permissions would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
guzzlehttp/psr7 Version ^2.7 | — | — |
psr/http-client Version ^1.0.3 | — | — |
yethee/tiktoken Version ^0.10.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.