The repository includes tests, the package has a clear MIT declaration, and releases have arrived regularly. Maintenance is concentrated in one contributor, and the project has no reported security policy or scanning tools.
78%
Total Score
83
100
88
50
All three recent commits came from one contributor, so maintenance continuity depends heavily on a single person. Organization backing provides some handoff capacity but does not remove the concentration concern.
The project uses Make and Composer for builds, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency but is not by itself a severe dependency risk.
Version 0.45.0 is not a prerelease and recent releases contain no prerelease versions, although the pre-1.0 major version signals some API maturity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.