Usable with caveats: the release is clearly packaged, licensed, and actively backed, but the project is only one day old and has a single contributor with no security policy. Depend on it only if you can accept limited evidence of long-term maintenance.
62%
Total Score
63
100
88
88
Only one registry account has publish access. This is a limited publishing base, and unlike an organization-backed project there is no provided organizational context to compensate for that concentration.
The package is only 1 day old with two releases, so there is not enough history to demonstrate sustained maintenance or reliability over time.
All recent repository commits come from one contributor, leaving maintenance dependent on a single person. The repository is user-owned, so no organization backing is provided to offset that concentration.
There was one commit by one active maintainer in the last 3 months, with the latest push occurring recently. This supports current activity but is too little history to establish durable maintenance.
Composer is used as a build tool, but no security-scanning tool is detected. The build setup is present, while security-process transparency remains limited.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.