The MIT license and focused file tree make the package easy to inspect. A single maintainer and no security policy leave limited evidence of support if issues arise.
58%
Total Score
50
88
83
One registry maintainer is consistent with the user-owned repository, but it leaves little visible publishing redundancy if that maintainer becomes unavailable.
This is a 1,167-day-old package with only one release and no releases in the past 12 months, which is meaningful abandonment risk for a dependency.
Composer build tooling is present, but no security scanning tools were detected, reducing automated oversight for a package that handles generated files.
The repository has no security policy, so users have no documented security-reporting path or stated response process.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.