The MIT license, clear README, focused dependency set, and matching source repository make the package straightforward to evaluate. Long-term support is less certain because ownership is concentrated in one user account and no security policy is published.
58%
Total Score
50
100
83
75
Only one registry maintainer, codex13, is listed, and the project backing identifies a user-owned repository rather than an organization. This leaves limited visible redundancy if the maintainer becomes unavailable.
The repository is owned by a user account, not an organization. Combined with the single registry maintainer, this indicates limited visible project backing.
The package is only 191 days old and has two releases, both published on the same day. That is too little history to demonstrate sustained maintenance, despite the rapid initial release interval.
The repository had zero commits and zero active maintainers in the last three months. For a package released only about six months ago, that provides weak evidence of ongoing maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this modestly lowers confidence in external adoption and review but is not decisive alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/string Version ^6.0 || ^7.0 | — | — |
webman/console Version * | — | — |
firebase/php-jwt Version >=6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.