The package includes a substantial README, tests, a matching MIT license, and no install-time scripts. It lacks a repository security policy, leaving modest transparency concerns for a young project.
67%
Total Score
50
86
75
This is a 34-day-old package with only one release, so there is little evidence of sustained maintenance or release maturity. Its recent publication partly limits how strongly this should be penalized.
All recorded recent commits came from a single contributor, creating a meaningful continuity risk for a small user-owned project.
The repository recorded one commit from one active maintainer during the last three months. That shows recent activity, but not enough sustained work to establish a reliable maintenance pattern.
No repository security policy was found, reducing transparency around vulnerability reporting and response. This is a modest concern rather than a severe dependency risk.
Version v0.1.0 is not a stable major release, which indicates an early API and greater change risk. There is no prerelease churn, but the package still has limited maturity evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^13.0 | — | — |
pomodocs/commonmark-alert Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.