The project has frequent releases, tests, release notes, and three active contributors. Check that its proprietary terms fit your distribution model and verify the repository linkage before adopting.
68%
Total Score
100
100
78
75
The manifest declares a proprietary license, with no detected license text or license file. This creates a real adoption and redistribution constraint for a package presented as open source.
The repository name does not match the package name, and its README does not mention the package. Although a name mismatch can be normal for a sub-package, the absence of any README reference makes package ownership or linkage less transparent.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, so this limits external validation but does not outweigh the active release and contributor history.
The repository has no published security policy. This is a transparency gap for reporting vulnerabilities, though active development and security scanning partly compensate.
Version v0.7.0 is not a stable major release, but it is not marked prerelease and recent releases have no prerelease share. The versioning indicates an evolving API rather than abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.27.0 | — | — |
league/flysystem Version ^3.0 | — | — |
gosuperscript/axiom Version ^0.6.0 | — | — |
gosuperscript/monads Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.