The repository has no stars or forks, and it provides no security policy, which limits outside validation and security transparency. Clear licensing, documentation, release notes, and a small dependency footprint offset these concerns.
62%
Total Score
67
100
83
83
Only one registry publishing account is listed. This is a modest resilience concern, though the linked repository confirms a corresponding individual project owner.
The repository is owned by an individual account rather than an organization, so there is no visible organizational backing to broaden maintenance capacity.
The package is about 360 days old but all three releases arrived within roughly one day, with no newer release since September 2025. That concentrated launch activity followed by a long quiet period raises maintenance risk.
The repository has zero stars, forks, and watchers, so there is no visible community validation or external adoption signal. Popularity is supporting evidence rather than a verdict, especially for a small package.
Composer is used as the build tool, but no security-scanning tooling is reported. That is a transparency and hygiene gap, not evidence of an unsafe release by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.