It has one registry maintainer, no tests, no security scanning, and unpinned workflow actions. The MIT license, matching repository, release notes, stable version, and no install scripts provide useful transparency.
56%
Total Score
50
88
75
One registry account has publish access, so release continuity depends on a single person. The linked repository is user-owned rather than organization-backed, providing no visible maintainer-base compensation.
This is the package's only release, published about 18 months ago, with no releases in the last 12 months. That leaves maintenance continuity unproven for a relatively new package.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the package having received no follow-up work since its initial release.
The project uses Composer and Make, but no security-scanning tooling was detected. That is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a hygiene gap for a library intended for application integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
compwright/easy-api Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.