The package has no runtime dependencies, a matching repository, tests, and a license file. Its pre-1.0 status and absent security policy leave modest maturity and transparency gaps.
76%
Total Score
50
100
86
75
All recent commits came from one contributor, leaving no demonstrated contributor redundancy. The matching repository and recent releases provide some continuity but do not remove the single-person dependency.
Only one commit was recorded in the last three months, with one active maintainer. For a young package this is a limited maintenance signal, though the recent release history shows it has not been abandoned.
Composer build tooling is present, but no security scanning tool was detected. This is a modest supply-chain hygiene gap rather than evidence of unsafe code.
The repository has no security policy, reducing clarity about vulnerability reporting and maintenance response. Its small scope and active release history provide limited compensation.
Version 0.1.8 is not yet at a stable major version, so API compatibility may still change. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.