The source is compact, documented, and straightforward to inspect. Its single-maintainer project has no recent commit activity, while release intervals are long and security oversight is minimal.
65%
Total Score
50
100
83
75
One registry account publishes the package, and the repository is user-owned rather than organization-backed. That creates a thin maintainer base, although the package is small and the latest release was recent.
The package is about 708 days old with only 3 releases, 1 in the last 12 months, and a median interval of about 302 days. This indicates a slow maintenance cadence, though the latest release is recent enough to avoid an abandonment verdict.
There were 0 commits and 0 active maintainers in the last 3 months. Although the latest release was recent, the lack of ongoing commit activity weakens confidence in continued maintenance.
Composer build tooling is present, but no security scanning tools were detected. For a package that generates authentication tokens, this is a meaningful security-hygiene gap.
The repository has no security policy. This limits transparency about vulnerability reporting and response expectations, though it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.