The source is small and offers little documented safety process. Organization backing and a declared MIT license help, but the package remains an immature, lightly maintained dependency.
43%
Total Score
50
67
75
The package has only two releases, with the latest published in September 2021 and none in the past 12 months. That long release gap raises abandonment and compatibility risk for a dependency.
The repository recorded zero commits and zero active maintainers in the past three months. Although its metadata shows a later push, the observed commit activity does not demonstrate ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected. That weakens automated assurance for a package with little recent maintenance evidence.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a meaningful transparency gap, though it does not by itself make the package unfit.
The assessed release is still v0.0.2 rather than a stable major release, indicating an immature API and greater risk of breaking changes or incomplete functionality.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.