The package includes tests, release notes, a useful README, and security scanning. Organization backing and Apache-2.0 licensing add reassurance, but workflow permissions and stale activity leave maintenance less certain.
63%
Total Score
75
100
94
67
The package has 14 releases over about 3 years, but only one release in the last 12 months. This indicates established publishing history with a noticeably slower recent cadence.
The repository had zero commits and zero active maintainers in the last 3 months. Together with the slow recent release cadence, this raises maintenance and abandonment concerns.
No security policy is present in the repository. This is a transparency gap, though organization backing and active security scanning partly reduce its weight.
All five workflow action references are unpinned, and a high-confidence medium-severity finding shows the release workflow exposes the entire secrets context. The workflows have no untrusted checkout or script-injection findings, but these release safeguards remain weak.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vonage/jwt Version ^0.5.0 | — | — |
vonage/client-core Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.