The package includes a substantial README, tests, exact release notes, and a matching Apache-2.0 license. Organization backing and a clean dependency and install profile help, but longer-term maintenance capacity is not yet demonstrated.
62%
Total Score
75
100
79
83
The package has only two releases, both published on the same day, so its release track record is too short to establish durable maintenance.
The repository shows zero commits and zero active maintainers over the last three months. Because the package is newly published, this is an important but early abandonment-risk signal rather than proof of abandonment.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and assurance gap.
The repository has no published security policy, which makes vulnerability reporting and response expectations less transparent.
Version 0.1.1 is a non-prerelease release, but it remains below a stable 1.0 major and has not yet demonstrated maturity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.