The small codebase has a clear license, release notes, and no install-time scripts. Maintenance depends on one contributor, with only one release and no security policy or scanning, so long-term support is uncertain.
62%
Total Score
67
100
83
75
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
The package is 72 days old with only one release, so there is not enough release history to establish a durable maintenance pattern.
One contributor made all six commits in the last three months, leaving no demonstrated handoff capacity if that contributor stops maintaining the project.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not determine health for a small package.
Composer is used for builds, but no security scanning tools are present. The missing scanning reduces supply-chain transparency, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.