Documentation is strong, and the repository includes tests and release notes. The single-contributor project, pre-1.0 version, absent security scanning, and unpinned CI actions leave more maintenance and build-integrity risk than a mature dependency.
68%
Total Score
67
100
86
75
The repository owner is an individual user rather than an organization, so the single-maintainer and bus-factor concerns are not offset by visible organizational backing.
All seven recent commits came from one contributor, so maintenance depends entirely on a single person and has a fragile handoff path.
Composer build tooling is present, but no security-scanning tool was detected; this is a meaningful gap for an engine that includes web and form-security components.
The repository has no security policy, leaving no documented channel or process for reporting and handling vulnerabilities in this security-relevant web package.
v0.1.3 is not a stable major release, so its public API and behavior may still change substantially despite the absence of prerelease labeling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^7.0 | — | — |
golovanov/traceloom Version ^0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.