This release appears usable and actively maintained, with 20 releases in 33 days, a recent repository push, a substantial 324-file source tree, documented tests and changelog support in the repository, a security policy, and no deprecation or dangerous workflow findings. However, it is a very young pre-1.0 package, all 28 recent commits come from one contributor, repository popularity and issue activity provide little external validation, and the workflow does not declare top-level token permissions. The proprietary license is explicitly declared and accompanied by a LICENSE.md file, so licensing is transparent, but adopters should review its terms and accept the maturity and maintainer-concentration risks before depending on it in a critical project.
68%
Total Score
50
100
72
90
The package declares a proprietary license and includes one LICENSE.md file, so the licensing status is transparent rather than an unlicensed gap. The proprietary terms may still require legal review before adoption.
Only one registry account has publish access. The linked repository is also owned by an individual rather than an organization, so there is no provided project-backing evidence to offset this concentration.
The repository owner is an individual account, not an organization, and no registry namespace is provided. This offers no organizational continuity evidence to compensate for the single-maintainer profile.
Twenty releases in 33 days, with a median interval of about 3 hours, show strong current shipping activity. The short history also means there is little long-term evidence of stability.
One contributor made all 28 commits in the last three months, with a 100% commit share. Because the repository is user-owned rather than organization-owned, this is a meaningful continuity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
symfony/http-client Version ^7.2 | — | — |
symfony/postmark-mailer Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.