The complete README, MIT licensing, and package-to-repository match improve transparency. Missing security scanning, unpinned workflow actions, and a very small project footprint leave meaningful maintenance and build-hygiene concerns.
54%
Total Score
25
75
67
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that ongoing maintenance may have slowed or stopped.
Only one registry maintainer is listed, which gives the release a thin publishing base; the individual-owned repository provides no evidence of a broader organization-backed team.
Four releases arrived within roughly one day, showing active initial publishing but too little history to demonstrate sustained maintenance.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity alone does not determine whether a small package is healthy.
Composer is used for the build, but no security-scanning tooling was detected, leaving automated vulnerability checking uncovered.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.