Usable with caveats: this is a brand-new, very small package with no demonstrated maintenance history. It has clear licensing and a matching README, but no tests, security policy, or repository activity yet.
58%
Total Score
50
100
75
88
The package was released only once, on the assessment date, and has no release track record yet. That limits evidence of maturity and maintenance, though its newness alone does not prove abandonment.
The repository has recorded zero commits and zero active maintainers in the last three months. Because the package is newly released, this is mainly a lack of demonstrated maintenance capacity rather than evidence of a long-term collapse.
The repository has zero stars, forks, and watchers, offering no community adoption signal. For a package released today this is expected, but it leaves maturity unvalidated.
Composer is used as the build tool, but no security scanning tools are present. The missing scanning is a modest transparency and maintenance gap, not an immediate dependency risk by itself.
The repository has no security policy, leaving reporting and response expectations undocumented. This is a hygiene gap for a package that processes application traffic, although it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.