It has a clear README, minimal runtime dependencies, and no install-time scripts. The license text differs from the declared license, while the lone maintainer, absent security controls, and recent lack of commits add maintenance risk.
60%
Total Score
50
100
88
75
The artifact and repository contain an MIT-0 license file, but the manifest declares MIT; this license mismatch creates a transparency concern despite the release being licensed.
Registry publishing is controlled by one maintainer. That is workable for a small package but leaves a thin maintainer base and increases bus-factor risk.
The package and repository are owned by the same individual account, confirming direct ownership but not providing organizational backing to compensate for the single-maintainer base.
There were no commits and no active maintainers in the last three months; for a young package, this suggests development has gone quiet and raises maintenance risk.
Composer build tooling is present, but no security-scanning tools are configured. This is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.