The package includes clear documentation, tests, an MIT declaration, and only two runtime requirements. Its organization-backed repository is linked correctly and not archived, but limited security tooling leaves less evidence for long-term maintenance.
58%
Total Score
75
100
83
75
This is the only release, published 190 days ago, so the project has limited history and no demonstrated release cadence. Its age is enough to provide some evidence, but not enough to establish sustained maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, reducing evidence that issues and fixes are being actively handled. The project is still relatively young, so this is a maintenance caution rather than proof of abandonment.
Composer is used for the build, which fits the package, but no security scanning tools are configured. That weakens repository hygiene and supply-chain transparency.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, though it does not by itself make the release unfit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.