The package is small and well-scaffolded, with tests, a README, matching source repository, MIT licensing, and no install-time scripts. No commits were made in the last three months, while the project has one maintainer, no security policy, and no security scanning.
60%
Total Score
50
100
79
83
Only one registry maintainer is listed. That is workable for a small personal project, but it leaves limited visible publishing redundancy.
The package is only 138 days old and all three releases arrived within roughly one day, leaving little evidence of sustained release maintenance beyond the initial launch.
The repository had zero commits and zero active maintainers during the last three months. For a package this new, that is a meaningful warning that maintenance may have stalled.
Composer is used for the build, but no security scanning tools were detected. The lack of scanning is a hygiene gap rather than evidence of abandonment.
The repository has no security policy. This reduces transparency about how vulnerabilities are reported and handled, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.