Usable with caveats: it has a clear README, tests, licensing, safe workflow permissions, and recent releases, but it is only 3 days old and has no recent security tooling or security policy. Treat it as an early-stage build-time dependency and monitor maintenance before broad adoption.
72%
Total Score
83
100
78
90
The package is only 3 days old with 3 releases and a median interval of about 1.5 days. This shows active initial iteration but provides very little long-term maintenance history.
The repository reports zero commits and zero active maintainers in the last 3 months, but the package itself is only 3 days old and was pushed recently, so this is an important coverage inconsistency rather than clear abandonment.
The repository has zero stars, forks, and watchers. For a package only 3 days old this is weak supporting evidence, but it is not by itself a dependency-health failure.
Composer build tooling is present, but no security scanning tools were detected. That leaves a security-process gap, although the repository's workflow and package structure provide some compensating transparency.
The repository has no SECURITY.md or other detected security policy, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.