The package is licensed, documented, and backed by a matching organization repository with tests. Its security posture is incomplete, and the workflow needs dependency pinning before production use.
61%
Total Score
75
79
67
This package was first released today, with all three releases occurring on the same day, so there is not yet evidence of sustained maintenance or release stability.
No commits or active maintainers were recorded in the last three months, but the repository and package are only one day old, making this primarily an unproven maintenance history rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and assurance gap.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
v0.3.0 is not a stable-major release, which is reasonable for a new package but indicates the API may still change.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.