Usable with caveats: this is a very new package with only two releases and no observed commit activity yet. It has a matching repository, tests there, clear licensing, and no deprecation or unsafe workflow findings, but its maintenance record is not established.
62%
Total Score
67
100
81
80
The package and repository are owned by the same individual account. That is consistent ownership, but it does not provide the redundancy or institutional backing of an organization-owned project.
The package is brand new: it is 0 days old and has only 2 releases, both published within minutes of each other. That provides little evidence of sustained maintenance or release maturity.
There were 0 commits and 0 active maintainers observed over the last 3 months. Because the repository was created only minutes earlier, this is best treated as an unproven maintenance record rather than evidence of abandonment.
The repository uses Composer build tooling, but no security scanning tool was detected. The missing scanner is a transparency gap, though it is not by itself a severe dependency risk.
No repository security policy was found. For a small, newly published generated-code library this is a modest transparency gap, but it leaves vulnerability-reporting expectations unspecified.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hershel-theodore-layton/sgml-stream Version dev-master || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.