Usable with caveats: the package is actively released, clearly licensed, and has a substantial README with notes for this version. Recent repository work is thin and comes from one contributor, while the project lacks a security policy and declared workflow permissions.
72%
Total Score
50
100
94
67
The registry namespace and repository owner match, but the owner is a user rather than an organization. The matching ownership supports authenticity, while the user-owned project provides limited redundancy for maintenance.
One contributor made 100% of the commits in the last three months. The repository is user-owned rather than organization-owned, so there is no organizational backing shown to offset this concentration.
Only one commit was recorded in the last three months, made by one active maintainer. Recent release activity compensates for some of this thin source activity, but the low current development volume remains a maintenance caution.
Composer build tooling is present, but no security-scanning tools were detected. This is a transparency and assurance gap for a package intended to handle messaging and authentication.
The repository has no security policy. That leaves vulnerability-reporting and response expectations undocumented, which is a real but not decisive health concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/crc32 Version ^0.1.0 | — | — |
protobuf-php/protobuf Version ^0.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.