The MIT license, release notes, and clear README improve transparency, while organization backing provides some continuity. However, only three releases exist and neither the registry nor repository shows activity for about 22 months; the repository README also does not mention this package.
57%
Total Score
100
100
72
75
The package has only three releases, with no release in about 22 months. This is a meaningful maintenance concern, although the latest release is stable and has documented release notes.
The repository name matches the package, but its README does not mention the package name. That weakens confidence that the repository documentation is specifically maintained for this published package.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but it is not decisive for a small, organization-backed package.
Composer is used for builds, but no security scanning tool is reported. This is a modest transparency and maintenance gap rather than a severe risk.
The repository is not archived, which preserves the possibility of future maintenance, but its last push was about 22 months ago and therefore does not offset the stale release history.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.