The repository includes tests, release notes, and a clear license. Workflow references are all unpinned, no security policy is provided, and the very short history cannot yet establish durable maintenance.
65%
Total Score
63
100
86
67
One registry publisher is listed, which concentrates publishing responsibility in a single person; the linked repository provides some backing but is also user-owned.
The package and repository align under the bx-shef namespace, but the repository owner is an individual rather than an organization, so institutional maintenance capacity is limited.
Only two releases exist, published within about one day, so the package has not demonstrated sustained release practice or maturity yet.
No commits or active maintainers were recorded over the last three months, but the package is only about one day old and has a recent push; this leaves long-term maintenance unproven rather than indicating abandonment.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.