The repository has clear organizational ownership, a usable README, and a small dependency surface. Composer tooling, security scanning, and read-only workflow permissions are reassuring, but the project has no security policy.
58%
Total Score
75
100
89
75
The package has only one release, published 501 days ago, with no releases in the last 12 months. That is a meaningful maintenance concern for a dependency, though the small package scope limits the impact.
There were zero commits and zero active maintainers in the last three months. Combined with the single-release history, this leaves ongoing maintenance uncertain.
The repository has zero stars and forks and one watcher. This is weak supporting evidence, but popularity alone does not outweigh the maintenance and ownership signals.
No repository security policy was found, leaving vulnerability-reporting expectations unclear. This is a transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.