Clear documentation, tests, MIT licensing, and organization backing support adoption. The small dependency footprint and package-specific repository are helpful, but the immature version line and limited recent activity leave maintenance uncertainty.
67%
Total Score
75
100
81
67
Seven releases across 606 days and two releases in the last year show the package is not abandoned, though the recent cadence is limited for a young integration library.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, even though a recent push and current release history provide some counterevidence.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap rather than evidence the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
Version v0.0.7 is not a prerelease, but the 0.0 major line signals that breaking API changes remain possible.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.