Its MIT licensing and matching source repository improve transparency, but the minimal documentation and absent security tooling leave little support for adoption.
42%
Total Score
0
69
50
Only two releases exist, both from December 2021, and there have been no releases for nearly five years. That leaves the package's maintenance and compatibility uncertain.
The repository recorded no commits and no active maintainers in the last three months, consistent with the package's long release gap. There is no newer activity to offset the abandonment concern.
The artifact includes a README and a GitHub release, while the absence of tests and a changelog is normal packaging practice. However, the README is only 54 characters, providing little integration guidance for a server tool.
Composer is used for the build, which supports reproducible project structure, but no security-scanning tooling is present. This is a modest transparency and maintenance gap rather than a severe risk.
The linked repository has no security policy, leaving no documented route for reporting vulnerabilities. This adds a small support and maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
uccu/swkoa-plugin Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.