Documentation, licensing, and a matching source repository make the package reasonably transparent. Its very recent history and lack of repository activity or security tooling leave maintenance and oversight uncertain.
58%
Total Score
25
88
75
The repository recorded zero commits and zero active maintainers during the last three months, despite the package being recently released; this is the strongest evidence that ongoing maintenance is uncertain.
Only one registry publisher is listed, which creates some bus-factor concern; the matching repository ownership and package references provide limited compensation but do not establish a broader maintenance base.
The package is only 58 days old and published four releases in a burst, with a median interval of about 42 minutes; this shows active initial delivery but little evidence of an established maintenance pattern.
Composer is used for the build, but no security scanning tools are present, leaving a notable oversight gap for a package that handles audit data and token-status review.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
eveseat/services Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.