Documentation, tests, licensing, and repository checks are solid. The project is only one day old, remains beta-only, and all recent commits come from one contributor, so its long-term maintenance is not yet proven.
68%
Total Score
63
100
86
67
The repository is owned by a user account rather than an organization, so the single-contributor concentration is not compensated by visible organizational backing.
Eleven releases were published within one day, showing active early iteration but providing almost no evidence of long-term maintenance.
One contributor owns 100% of the recent commits, leaving no demonstrated maintenance redundancy.
Only three commits were recorded in the past three months, all in the package's first day, so the longer-term commit record is not yet established.
The repository has no security policy, which is a minor transparency gap for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.9 | — | — |
carthage-software/mago Version 1.50.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.