The package includes a useful README, changelog, release notes, tests in the repository, and a clear MIT license. Its main limitation is that it is very new and recent work is concentrated in one contributor, while workflow references are unpinned.
64%
Total Score
67
79
50
The package is only 47 days old with three releases, all within the last 12 months and spaced about 1 day apart. This shows initial activity but provides little evidence of long-term maintenance.
One contributor made all three commits in the last three months. Organization backing provides some handoff capacity, but the observed maintenance activity is still concentrated.
The repository recorded three commits in the last three months, showing some recent activity. The small volume is understandable for a new package but does not yet demonstrate sustained maintenance.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. This is a modest transparency and assurance gap, not evidence of unsafe code.
No repository security policy was found. For a package implementing a network-facing health protocol, this reduces the project's documented vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.1 | — | — |
amphp/pipeline Version ^1.2 | — | — |
thesis/protobuf Version ^0.2 | — | — |
thesis/grpc-client Version ^0.2 | — | — |
thesis/grpc-server Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.