The package includes tests, documentation, and a small dependency surface. Its post-install script, prerelease status, and lack of a security policy add modest operational concerns.
62%
Total Score
75
100
81
67
A post-install command runs during installation, adding execution-time supply-chain and reproducibility exposure compared with a package without install scripts.
The package is 410 days old but has only one release, with no releases in the last 12 months. That limits evidence of sustained maintenance and makes adoption less reassuring.
There were no commits and no active maintainers in the last 3 months. Although the repository is not archived, this provides weak evidence of current maintenance.
The repository uses Composer, but no security scanning tool was detected. That is a modest transparency and maintenance gap for a dependency.
The repository has no security policy. This does not show a vulnerability, but it leaves reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.