The package has a clear README, a matching repository, and four releases in the past year. Its organization backing and focused scope help, but security scanning and a security policy are absent.
58%
Total Score
67
86
75
Only one account has registry publish access, which is a thin publishing base; the organization-owned repository provides some backing but does not remove single-person publishing dependence.
There were no commits and no active maintainers in the last three months, indicating maintenance has gone quiet and increasing abandonment risk.
Composer is used for builds, but no security scanning tools are present, leaving a repository hygiene gap without making the release unfit on its own.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
Version v0.1.3 is not a stable major release, so its API may still change; it is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.