Healthy and reasonable to adopt, with a clear license, frequent recent releases, and an active organization-backed repository. The main concerns are that all recent commits come from one contributor and the repository does not clearly identify or mention this package; no security policy is published.
78%
Total Score
67
88
83
One contributor made all 6 recent commits, creating a meaningful single-maintainer continuity risk. Organization backing partly compensates because maintenance can potentially be handed off.
The repository recorded 6 commits in the last 3 months and 1 active maintainer, which demonstrates recent activity but limited visible maintenance capacity.
The repository name does not exactly match the package name and its README does not mention the package, so it is not fully clear that the linked repository specifically backs this release.
Composer is used as a build tool, which supports reproducible project structure, but no security scanning tools are reported. The lack of scanning lowers assurance somewhat without outweighing the active release history.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented. This is a transparency gap, though it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.