The matching repository, MIT licensing, release notes, and organization ownership provide clear provenance. No security policy or automated security scanning is present, so confidence in the project’s longer-term operating practices is limited.
73%
Total Score
75
86
50
This is the first release, published less than a day ago, so there is no release history to demonstrate sustained maintenance or compatibility practices. Its very recent launch explains the absence of older releases but does not remove the maturity gap.
No commits or active maintainers were observed in the last three months, but the package is newly released and the repository was pushed shortly before collection. This limits evidence of ongoing maintenance rather than proving abandonment.
Composer build tooling is present, but no security scanning tools were detected. For a non-executable documentation package this is a modest process gap, not a severe dependency risk.
The linked repository has no security policy. This reduces transparency about vulnerability reporting and handling, though the package contains prose rather than runtime code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.