The project is still very young, with only three releases in 58 days and no established adoption signal. It has strong documentation, tests, release notes, an organization-backed repository, and no deprecation or archive warning.
68%
Total Score
100
100
83
67
The package is only 58 days old with three releases, all within a short 5-day period; this shows initial activity but not yet a long maintenance record.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, though low popularity alone does not make a young, organization-backed package unsafe to depend on.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
Version v0.1.2 is not on a stable major version, so its API and behavior may still change substantially even though it is not marked as a prerelease.
Both workflows were analyzed successfully with no audit findings or untrusted sinks, but all five action references are unpinned and one publishing workflow grants top-level write permissions. The write scope is only a mild concern because no untrusted workflow path was found.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mcp/sdk Version >=0.7.0 <0.8.0 | — | — |
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
symfony/uid Version ^5.4 || ^6.4 || ^7.3 || ^8.0 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.