Usable with caveats: this is a transparent, lightweight alpha package with clear documentation and a matching source repository, but it has only one release and no commits in the last three months. Treat it as an early-stage dependency until maintenance becomes more established.
56%
Total Score
50
100
75
75
The package includes a substantial README, and the absence of tests or a changelog in the published artifact is normal packaging practice. However, the repository also reports no tests or changelog, so there is little evidence of ongoing verification or release documentation.
The package is 135 days old but has only one release, so there is not yet enough release history to demonstrate sustained maintenance or stability.
The repository has recorded zero commits and zero active maintainers during the last three months, which is a meaningful maintenance concern for a package still in alpha.
The repository uses Composer build tooling, but no security scanning tools are reported. The missing scanning is a hygiene gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled. This is a moderate governance gap for a settings package that advertises encryption and tenant isolation features.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.