The repository is active enough to avoid abandonment concerns, and there are no install-time scripts or workflow findings. Limited security tooling and a single individual maintainer leave little evidence of ongoing support.
58%
Total Score
50
79
67
One registry maintainer is consistent with an individually owned project, but it creates a narrow publishing and support base with no demonstrated redundancy.
The repository and artifact each contain only 13 files, indicating a very small project surface with limited visible documentation or supporting material. This is not severe by itself but provides little maturity evidence.
The artifact has no README, which makes a small library harder for consumers to understand and integrate. Missing tests and a changelog are normal for published artifacts and do not add concern here.
The package is only 21 days old and has one release, so there is not yet enough release history to demonstrate sustained maintenance or stability.
Composer build tooling is present, but no security-scanning tool is reported. That leaves a meaningful transparency gap for a package this new.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.