The package includes tests, a clear README, matching Apache-2.0 licensing, and organization backing. Its repository has no security policy or security scanning, so reassess as the project matures.
65%
Total Score
100
79
50
The package is only 1 day old, despite having 5 releases in that period; this shows active initial publishing but provides almost no long-term maintenance track record.
Composer build tooling is present, but no security scanning tools were detected. That reduces automated supply-chain hygiene, though it is not evidence of a defect by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a package intended for project integration.
Version 0.1.7 is not a stable major release, so its API and behavior may still change substantially. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
opis/json-schema Version 2.6.0 | — | — |
onematrix/tracing-sdk Version 1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.