The README and source layout are clear, and the repository is backed by an organization. Its very short history and single active contributor leave maintenance continuity uncertain, while the license mismatch needs clarification.
58%
Total Score
67
100
79
83
The manifest declares Apache-2.0, but the artifact license file was detected as MIT; although licensing files are present, the mismatch should be resolved before adoption.
The package is only 2 days old with two releases, so there is not enough history to demonstrate sustained maintenance or reliable release practices.
One contributor made 100% of the three recent commits. Organization backing provides some handoff capacity, but no second active contributor is evidenced.
The repository has only 3 commits in the last 3 months, all during this newly created release period, so longer-term maintenance capacity is unproven.
The repository has no security policy. This is a transparency gap for a package exposing application data through GraphQL, though it is not severe on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
elephentity/runtime Version ^0.10 || ^0.11 | — | — |
webonyx/graphql-php Version ^15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.