The MIT license, substantial README, repository tests, and no install-time scripts improve transparency and adoption safety. The organization-owned repository and recent commits provide some backing, but the project has little history.
62%
Total Score
67
79
67
The package is about one day old, with four releases clustered in that period. This shows active initial work but provides no meaningful long-term maintenance record.
One contributor made all 12 recent commits, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity, but no second active contributor is shown.
There were 12 commits in the last three months, all within the recent project window. This indicates current activity but cannot yet demonstrate sustained maintenance.
Composer build tooling is present, but no security-scanning tool was detected. For a new library this is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified. This is a documentation gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^8.2 | — | — |
cakephp/collection Version ^4.0||^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.