The README, release notes, MIT license, and small runtime dependency set make integration straightforward. The minimal five-file project has no automated security scanning, so ongoing maintenance should be watched.
64%
Total Score
63
100
89
83
The package and repository are owned by the same individual user, which supports identity alignment but does not provide organizational maintenance redundancy.
The package is only 36 days old and has one release, so its maintenance track record is not yet established.
All recent commits came from one contributor, leaving maintenance dependent on a single person. The repository is user-owned rather than organization-backed, so there is no shown handoff capacity to offset this concentration.
There was one commit in the last three months from one active maintainer; this is consistent with a new package but provides little evidence of sustained maintenance.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/support Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.