Its MIT license, focused dependency set, and substantial documentation help adoption. The project is too new to establish dependable long-term maintenance, so this release warrants caution for production use.
58%
Total Score
50
100
88
83
Only one registry maintainer account is listed. Because the repository owner is a user account rather than an organization, there is limited visible publishing redundancy.
The registry namespace and repository owner match, but the owner is identified as a user rather than an organization, so there is no demonstrated organizational backing to offset the thin maintainer base.
The package is only 0 days old with three releases in roughly 5 hours, so there is not yet enough history to demonstrate sustained maintenance or release reliability.
The repository records zero commits and zero active maintainers over the last 3 months. The package is brand new, which explains this result but still leaves long-term maintenance unproven.
Composer is used as the build tool, but no security scanning tools are configured. That reduces automated oversight for a framework handling authentication and database operations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.