The package is very young, though three releases arrived about weekly and the repository is not archived. MIT licensing, a minimal dependency set, and organization backing reduce adoption risk.
68%
Total Score
83
100
79
50
The artifact contains no README, tests, or changelog, while the repository also reports no tests or changelog. The tiny package may explain the sparse artifact, but the lack of repository validation remains a maintenance gap.
All four recent commits came from one contributor, creating a meaningful single-maintainer continuity risk. Organization backing provides some ability to transfer maintenance, but no second active contributor is shown.
Composer is used for builds, but no security-scanning tooling is reported, leaving repository-level dependency or code checks unobserved.
The repository has no security policy, reducing clarity about vulnerability reporting and maintainer response expectations.
Version v0.7.0 is not a prerelease, but the package remains below 1.0, so its public API may still change as the young project matures.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.