The package has clear documentation, a complete source tree, an MIT license, organizational backing, and no install-time scripts. Its only release is brand new, so maintenance history is unproven; all six workflow actions are also unpinned.
67%
Total Score
75
100
79
75
This is the first release, published today, so there is no release cadence or history to demonstrate sustained maintenance. Its age makes the absence of history expected rather than evidence of abandonment.
There were no commits or active maintainers in the last three months, but the repository was only created or updated today. This leaves future maintenance unproven without showing abandonment.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a modest transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and handling expectations unspecified. For a newly published API client this is a minor governance gap.
Version 0.1.0 is not a stable major release, which suggests the API may still change. It is not marked as a prerelease, providing some compensation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.