Usable with caveats: it has a clear MIT license, thorough documentation, tests, frequent recent releases, and an active repository. It is still a very young 0.0.x package, with only one contributor responsible for all commits in the last three months and no security policy.
72%
Total Score
50
100
88
83
The package and repository are owned by the same individual account, so the source link is coherent, but there is no organization backing to provide additional maintenance capacity.
The package is only 43 days old but has 13 releases, including 5 in the last 12 months and a median interval of about 6 days. That shows active iteration, though the short history limits evidence of long-term maintenance.
One contributor made 100% of the commits in the last three months, creating a clear single-maintainer continuity risk. No organization backing is present to offset that concentration.
Only one commit was recorded in the last three months from one active maintainer. Recent releases provide some compensating evidence, but the repository activity itself is sparse.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a modest transparency gap for a package that processes application memory and storage.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
doctrine/dbal Version ^4.3 | — | — |
symfony/clock Version ^8.0 | — | — |
helgesverre/toon Version ^3.1 | — | — |
ineersa/hatfield-extension-api Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.