This is a clean, coherent first release with an MIT license, a matching organization-owned repository, tests included in both the artifact and repository, no install-time scripts, no deprecation, and a small runtime dependency surface. However, the package is brand new with only one release, has no demonstrated maintenance or adoption history, provides no security policy or security scanning, and has no repository workflows; these gaps limit confidence in long-term maintenance and release provenance. It is reasonable to evaluate or adopt with normal caution, but it lacks the maturity evidence expected for a highly trusted dependency.
62%
Total Score
83
100
78
80
No GitHub Actions workflows were found, so no dangerous workflow patterns were detected. This also means there is no observed CI automation supporting build or release assurance.
This package is 0 days old and has only one release, so there is no history demonstrating sustained maintenance, compatibility handling, or release reliability.
There are no issues or pull requests and no recent activity. With a same-day first release, this is inconclusive rather than a severe maintenance failure, but it provides no community-health evidence.
The repository has zero stars, forks, and watchers. For a package released today this is weak adoption evidence, but it is not by itself evidence of abandonment.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning reduces supply-chain transparency for future changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.