Usable with caveats: this is a well-documented, tested, organization-backed first release, but it has no maintenance history yet and the repository lacks security scanning. Reassess after it has established release and commit activity.
68%
Total Score
83
100
75
90
The package was released only minutes ago and has just one release, so there is no track record for maintenance or release stability yet.
There were no commits or active maintainers in the preceding three months, but this is partly explained by the package being newly released; it still leaves maintenance capacity unproven.
The repository has no stars, forks, or watchers. This is expected for a release created minutes ago and is supporting evidence only, not a standalone health failure.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful repository hygiene gap for a native extension.
Two workflows omit top-level token permissions and the release workflow grants write permissions, increasing CI credential exposure compared with a least-privilege setup.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.