Usable with caveats: the release is well documented, licensed, tested, and backed by a matching organization repository. However, it is a brand-new v0.1.0 with no release track record, and the repository lacks a security policy and explicit workflow token permissions.
68%
Total Score
75
100
83
80
This is the first release, published today, with no prior release cadence to demonstrate sustained maintenance or compatibility stability.
There are no commits or active maintainers recorded in the last three months, but the repository was only created and pushed today, so this primarily reflects limited history rather than demonstrated abandonment.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest assurance gap for a new package.
The repository has no security policy, so consumers lack documented guidance for reporting vulnerabilities or handling security issues.
The single workflow has no top-level token permissions declaration; although no write permissions were detected, explicitly limiting the token would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
psr/simple-cache Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.