The repository is active, has two contributors, tests, release notes, and organization backing. Its limited release history and absent security policy or scanning leave less evidence than a mature project.
82%
Total Score
100
100
75
75
Only two releases have been published, with the package less than one day old; this is too little history to establish long-term maintenance reliability.
The repository has one star and one fork, so external adoption evidence is limited; this is a minor concern for a package released less than one day ago and does not outweigh active development.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and assurance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear.
The assessed version is not a prerelease, but it is an early 0.x release and the recent prerelease share is 50%, so API and maintenance stability remain less established.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.