Usable with caveats: it has a clear MIT license, a complete small artifact, and frequent stable releases, but all recent commits come from one contributor and the repository has no security policy or scanning.
72%
Total Score
63
89
90
One contributor made all 9 commits in the last 3 months, creating a real continuity risk. Organization ownership provides some potential handoff capacity, but no second active contributor is shown.
The repository had 9 commits in the last 3 months, showing recent work, but all activity came from only one active maintainer.
There are no open issues or pull requests and no activity in the last month; this is neutral for a small guidelines package but provides little evidence of external review.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, though low popularity alone does not make a small package unsafe to use.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a transparency gap, although this package contains only guideline files and has no install scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.