This is a clean, very small Composer package with an MIT license, a complete minimal file tree, no install-time lifecycle scripts, no deprecation notice, and organization-backed repository ownership. However, it is newly published with only one release and no observed commit activity, tests, changelog, security policy, or security-scanning tooling. Those gaps are less concerning for a minimal Hello World library than they would be for a complex package, but the release has little demonstrated maintenance history, so adoption warrants normal verification and monitoring.
65%
Total Score
83
100
78
90
A README is present, but neither the artifact nor repository contains tests or a changelog. For a minimal example package this is understandable, though it leaves limited evidence of validation and release transparency.
Only one release exists and the package is 0 days old, so there is no demonstrated release or maintenance track record yet.
There were zero commits and zero active maintainers in the measured three-month window. Because the package is newly created, this mainly indicates insufficient maintenance history rather than confirmed abandonment, but it lowers confidence in ongoing support.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but the package is newly published and popularity is not decisive for a tiny library.
Composer is used as the build tool, but no security-scanning tooling is present. The lack of scanning is a hygiene gap, although the package is unusually small and has no complex build process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.