Documentation and tests are present, and installation has no lifecycle scripts. The repository is not archived and the package is MIT-licensed, but its short track record limits confidence.
58%
Total Score
50
100
81
83
The package is only 165 days old, with six releases concentrated between April 9 and April 11; the roughly 34-minute median interval suggests an early burst rather than an established cadence.
The repository recorded zero commits and zero active maintainers in the last three months. With no newer activity shown, ongoing maintenance capacity is uncertain.
The repository has zero stars, forks, and watchers. This provides no external adoption evidence, but popularity is supporting evidence rather than a health verdict.
Composer build tooling is present, but no security-scanning tool was detected. That is a maintenance and transparency gap for a KYC SDK, though it is not evidence of a security incident by itself.
The repository has no security policy. For an SDK handling identity-verification data, the missing disclosure process lowers transparency and makes vulnerability reporting less clear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.