A single runtime dependency keeps integration simple, but the project offers no security policy or scanning. Organization backing and clean install metadata provide limited reassurance for a very early release.
42%
Total Score
67
100
75
75
The published artifact contains only composer.json and one source file, matching a very small package but leaving little evidence of testing, documentation, or release safeguards.
The artifact has no README, while the absence of tests and a changelog is normal packaging practice. For a small library, missing consumer documentation remains a meaningful gap.
This is the package's only release, published 285 days ago, so there is no demonstrated release cadence or evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, with its last push occurring at the initial release, indicating no observed follow-up maintenance.
There has been no issue or pull-request activity in the last month. This is not inherently negative for a small package, but it provides no evidence of active support.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.