The artifact has a substantial README, tests, and a very small runtime dependency surface. It is not deprecated or archived, and its stable versioning is reassuring. The missing license and absent security policy reduce transparency.
52%
Total Score
0
100
81
75
There were zero commits and zero active maintainers in the last three months. For a package only 152 days old, this is a meaningful abandonment concern despite the repository remaining accessible.
No declared license, license file, or repository license file was detected. This creates a real transparency and reuse concern for a dependency.
The package is young at 152 days, with three releases concentrated between late April and early May; this provides limited evidence of long-term maintenance.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest supply-chain hygiene gap, not evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and handling expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.