The package includes a detailed README, repository tests, and a small dependency surface. Pin a later release once maintenance history develops.
66%
Total Score
50
100
81
67
This is the first release, published today, so there is no track record yet for maintenance or release continuity. Its age makes the absence of history understandable, but maturity remains unproven.
The repository records zero commits and zero active maintainers in the last three months. Because the package was released today, this mainly means maintenance capacity is not yet demonstrated rather than showing established abandonment.
The repository uses Composer and Just for build tasks, but no security-scanning tool was detected. This is a modest transparency and hygiene gap, not a severe dependency risk on its own.
No security policy is present in the repository. For a new analyzer extension this reduces vulnerability-reporting transparency, although it does not by itself indicate unsafe code.
Version 0.1.0 is an early, non-stable-major release, which implies that compatibility and behavior may still change. No prerelease label provides a small compensating signal, but the project is still at an initial version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
carthage-software/mago Version ^1.50 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.