Clear licensing, a coherent source tree, and no install-time scripts reduce avoidable adoption risk. The very short history and limited project safeguards leave maintenance less proven than an established dependency.
58%
Total Score
50
81
88
A changelog and README are present, but the README contains only 17 characters and the package has no tests. The missing tests are common packaging practice, while the extremely sparse consumer documentation is a real transparency gap for a library.
The package is only 49 days old and has one release, so there is not enough history to demonstrate sustained maintenance or release stability.
All recent commits came from one contributor, so maintenance depends entirely on a single person; the repository owner is an individual rather than an organization.
The repository recorded only one commit in the last 3 months from one active maintainer, providing limited evidence of ongoing maintenance.
Composer build tooling is present, but no security-scanning tooling was detected, leaving an additional maintenance safeguard unverified.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.