This release appears usable and reasonably well-supported, with a valid BSD-3-Clause license, a matching repository, active recent development, repository tests and changelog coverage, security scanning, and no deprecation or archival status. The main concerns are that the package is very new at 13 days old, all eight recent commits come from one contributor, and both workflows omit top-level token permissions; organization backing and the repository’s security policy partially mitigate the maintainer-concentration concern, but the package still has limited maturity history.
78%
Total Score
90
100
94
90
The package is only 13 days old with three releases and a median release interval of about 6.6 days, so it shows initial activity but has little long-term maintenance history.
One contributor made all eight recent commits, creating a low bus factor; organization ownership provides some ability to hand maintenance off, but no second active contributor is shown.
Both workflows omit top-level token permission declarations. Although no write permissions are explicitly requested, the lack of least-privilege declarations is a workflow-hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiirocks/voyti-2fa Version ^1.0 | — | — |
chillerlan/2fa-qrcode-bundle Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.