The package has tests, a changelog, a focused dependency set, and organization-backed ownership. The artifact identifies AGPL-3.0 while the manifest declares MIT, so confirm the applicable license before adopting it; no commits were recorded in the last three months.
68%
Total Score
75
100
86
50
The manifest declares MIT, but the artifact license file is detected as AGPL-3.0; although a license file is present, this unresolved mismatch creates a material adoption concern.
No commits and no active maintainers were recorded during the last 3 months, which weakens evidence of ongoing maintenance despite the recent release and repository push.
The repository uses Make and Composer build tooling, but no security scanning tools were detected; the missing scanning is a modest hygiene gap rather than an abandonment indicator.
The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.