Usable with caveats: the release is active, stable, documented, tested, and backed by a matching organization repository. Dependence is less comfortable because the package has no license file or declaration, and all recent repository work comes from one contributor without security scanning or explicit workflow permissions.
72%
Total Score
67
100
89
80
No license declaration or license file was found in the package or repository, leaving the legal terms for downstream use unclear.
All four recent commits came from one contributor, creating a meaningful continuity risk; organization backing provides some capacity to hand maintenance off, but no second active contributor is shown.
Four commits occurred in the last three months, indicating recent work, but the activity level is modest for a newly released package.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap that is relevant to a package distributed as a dependency.
The repository has no security policy, making vulnerability reporting and maintainer response expectations less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.