Invisible CAPTCHA alternative: honeypot, single-use timed tokens, proof of work, rate limiting, IP reputation and gibberish detection.
62%
Total Score
caution
This is a very new package with no recent commits and one registry maintainer, despite solid documentation and repository hygiene.
One registry maintainer is consistent with an individual-owned project, but it leaves the release process dependent on a single person and offers limited bus-factor evidence.
The package is only 0 days old with three releases, all published within roughly 1 hour, so there is not yet evidence of a sustained maintenance pattern.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the project is newly published, this is an early maintenance concern rather than proof of abandonment.
There were no new or closed issues or pull requests in the last month. For a package this new, the absence of activity provides little evidence of an established support process.
v0.2.0 is not a stable major release, which indicates an early API and maturity stage even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.