The MIT license, clear README, test suite, and organization-backed repository provide a solid starting point. Missing security policy and scanning, alongside no commits in three months, leave maintenance and security assurance relatively thin.
62%
Total Score
75
100
79
75
The package is only 116 days old and has two releases, both published on the same day. This is too little history to establish dependable maintenance, so it warrants caution.
There were zero commits and zero active maintainers in the past three months, despite the repository being only 116 days old. That leaves no observed ongoing maintenance after the initial release burst.
Composer build tooling is present, but no security scanning tools were detected. The build setup is appropriate, while security assurance remains limited.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations.
Version v0.1.1 is a pre-1.0 release, which signals an early and potentially changing API. It is not marked as a prerelease, providing some counterweight but not maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.