The MIT license, release notes, and organization-owned repository provide useful provenance. Its focused generated-code layout and lack of security tooling leave limited evidence that problems will be caught or addressed.
46%
Total Score
100
71
This package has made only one release, with no releases in the last 12 months; the sole release was nearly two years ago. That is strong evidence of an inactive or unfinished dependency.
Composer is used for the build, but no security scanning tools are configured. This is a modest transparency and maintenance gap, especially for a package with little recent activity.
Version 0.1 is not a stable major release, which fits an early-stage library but adds compatibility and maturity risk alongside the lack of subsequent releases.
No GitHub Actions workflows were present, so there are no workflow permission or unpinned-action findings. This also means there is no automated workflow evidence supporting ongoing validation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.