Clear documentation, tests, and a matching MIT license reduce integration friction. There is no security policy, while the small dependency set and no install hooks limit operational complexity.
60%
Total Score
50
100
88
83
The repository owner is an individual account rather than an organization, so the concentrated contributor activity is not visibly compensated by broader project backing.
The package is only 0 days old, with all five releases published on the same day. This provides too little history to demonstrate sustained maintenance or release discipline.
One contributor made all two commits in the last three months, concentrating maintenance knowledge and creating a meaningful continuity risk. The repository owner is an individual account, so no organizational handoff is shown to offset that concentration.
Only two commits were recorded in the last three months, so ongoing maintenance evidence is limited. This is partly explained by the package being newly published, but it still leaves its longer-term support unproven.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest process gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
inventorai/sdk Version ^1.3 | — | — |
illuminate/support Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.