Offline-verifiable QR records with versioned domain profiles
60%
Total Score
caution
A brand-new package with no established commit history carries meaningful maintenance risk.
Only two releases exist, both published within the first day of the package's recorded history, so there is not yet evidence of sustained maintenance or release stability.
The repository shows zero commits and zero active maintainers over the last three months; because the repository was created very recently, this is mainly a lack of evidence rather than proof of abandonment.
The linked repository has no security policy, which leaves vulnerability-reporting expectations unclear for a package handling signing and verification workflows.
Version v0.2.0 is not a prerelease, but the package is still below a stable major version and has too little history to demonstrate maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^8.0 | — | — |
symfony/process Version ^8.0 | — | — |
bacon/bacon-qr-code Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.