The package is a tiny, clearly licensed demo with a matching repository and no install-time scripts. Its pre-1.0 version and lack of recent commit activity leave maintenance and maturity uncertain, while the repository has no security scanning.
48%
Total Score
50
33
Only two releases were published, both nearly four years ago, with no releases in the last 12 months. The repository is not archived, but the registry history still indicates weak release maintenance.
The repository recorded no commits or active maintainers in the last 3 months. Its non-archived status and later push timestamp provide limited compensation, but do not show sustained development.
Composer is used for the build, which is appropriate, but no security scanning tooling was detected. For a small demo this is a modest transparency and maintenance gap rather than a severe risk.
This is a pre-1.0 release, so its API and behavior may change unexpectedly and its maturity is limited. No prerelease label partly reduces the instability concern, but does not establish production readiness.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.