The package is clearly licensed and its repository matches the package. Its small footprint and lack of security tooling leave less evidence of ongoing quality assurance.
58%
Total Score
75
81
83
The artifact has no README, while the absence of tests and a changelog is normal packaging practice for many compiled or framework-module releases. The missing consumer documentation is a minor gap.
This is the only release, published over a year ago, with no releases in the last 12 months. That provides limited evidence of continued maintenance.
The repository recorded no commits and no active maintainers during the last three months, reinforcing the maintenance concern from the single-release history.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest assurance gap for a package intended to be integrated into applications.
The repository has no published security policy, which reduces transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.