Tests, documentation, and a matching source repository provide useful context for consumers. The MIT license and lack of deprecation are reassuring, but the project has no security policy and its workflow actions are not pinned. Pin version 0.0.3 if adopting it.
68%
Total Score
50
78
75
The repository owner is an individual user rather than an organization, so there is no demonstrated organizational backing to offset the thin activity and small audience.
The package is about 17 months old with three releases and one release in the last 12 months, indicating a modest rather than highly active release cadence.
There were no commits and no active maintainers during the last three months, which is a concrete sign that maintenance may have slowed.
The repository has zero stars and forks and only one watcher, providing little community validation or evidence of a broad user base.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap for a package that controls access to JSON-RPC services.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3 | — | — |
symfony/config Version ^7.3 | — | — |
symfony/stopwatch Version ^7.3 | — | — |
symfony/http-kernel Version ^7.3 | — | — |
tourze/json-rpc-core Version 1.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.