The package includes substantial documentation, tests, and a clear MIT license, with organization backing. Its workflows use unpinned actions, and the repository has no security policy or scanning tools.
66%
Total Score
75
79
67
Only one release exists, published about 13 months ago, with none in the last 12 months. This leaves limited evidence of an established release and maintenance cadence.
There were no commits and no active maintainers in the last three months. For a package with only one release, this weakens evidence that maintenance is continuing.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.1.0 is not a stable major release, so the API may still evolve. It is not marked as a prerelease, which provides some compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.