The package is very young and has no recorded commits or active maintainers in the last three months. Its organization backing, matching repository, clear README, license, and lack of install scripts provide useful reassurance, but testing and security-policy coverage are limited.
68%
Total Score
75
71
75
A substantial 7,713-character README documents installation and configuration. Tests and a changelog are absent from the published artifact and repository, which is a meaningful maturity gap for a middleware library.
Only two releases exist across the package's first 148 days, with releases about 6 days apart. This shows initial activity but provides little evidence of a mature, sustained maintenance pattern.
The repository recorded zero commits and zero active maintainers during the last three months. For a package only 148 days old, that is a caution about maintenance continuity rather than evidence of abandonment on its own.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and process gap, not a severe supply-chain concern.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear, though the absence of a policy alone does not show that issues would be ignored.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^13.4 || ^14.0 | — | — |
symfony/rate-limiter Version ^7.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.