The package includes a README, release notes, Composer tooling, and Dependabot coverage. Its organization-backed repository is not archived, but the very small project footprint limits confidence.
64%
Total Score
75
100
88
88
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. That limits transparency for an open-source dependency.
The repository recorded no commits and no active maintainers in the last three months, despite the release being roughly three months old. This raises a maintenance concern, though the repository was pushed on the release date.
The repository has no published security policy. That is a transparency gap, although the package does have Dependabot configured.
The release is not a prerelease and the recent prerelease share is zero, supporting stable consumption. The reported latest version being 1.1.0 while assessing 2.0.1 is inconsistent and modestly reduces confidence in the registry metadata.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.