A single maintainer, one release, and no commits in the past three months limit confidence in ongoing support. The README, tests, release notes, MIT declaration, and small dependency surface provide useful adoption evidence, while workflow pinning and security documentation remain weak.
61%
Total Score
50
100
79
75
Only one registry maintainer is listed, leaving limited visible publishing redundancy. The repository is user-owned, so this is not offset by organization backing.
The package is about five months old but has only one release, so there is little evidence of sustained maintenance or release reliability.
The repository recorded zero commits and zero active maintainers in the past three months, despite being only about five months old; ongoing support is therefore unproven.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, making vulnerability reporting and response expectations unclear for a web-server component.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.