This is a usable and reasonably healthy young package: it has a stable v1.1.0 release, an active non-archived repository, recent releases and commits, organization backing, a matching repository with package references, clear licensing, and no install-time lifecycle scripts or deprecation. Its main limitations are limited maturity—only three releases over 197 days—low adoption, no tests or changelog, no security policy, and no security scanning, so it merits normal dependency review and monitoring rather than being treated as a deeply established dependency.
78%
Total Score
100
100
78
90
A substantial README documents usage and deployment, but the artifact and repository contain neither tests nor a changelog; for a small CLI tool this is a genuine transparency and maintenance gap.
The package is young at 197 days and has only three releases, with a median interval of about 99 days; this indicates limited maturity, though releases are still occurring and the latest release is recent.
The repository has only 2 stars, 0 forks, and 1 watcher, indicating minimal external adoption. Popularity is supporting evidence rather than a verdict, so this lowers maturity confidence but is not a severe health issue.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a hygiene gap for supply-chain transparency, though it is not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.