The six-file module has a usable README and minimal runtime dependencies. Organization backing helps offset the single-contributor pattern, but there is no repository security policy.
67%
Total Score
67
100
88
50
The package has four releases since October 2019, with a median interval of about 2 years 7 months, although one release arrived in the last 12 months. This shows a usable but infrequent maintenance cadence.
All recent commits come from one contributor, creating concentration risk. The organization-owned repository provides some capacity to hand maintenance off, so this is a caution rather than a severe risk.
The repository has one commit and one active maintainer in the last three months. Recent activity is positive, but the amount of activity is too limited to demonstrate a strong maintenance rhythm.
Composer is used for builds, but no security scanning tool is present. For a small module this is a modest transparency and maintenance gap rather than evidence of unfitness.
The repository has no security policy. That weakens disclosure and response transparency, though it does not by itself indicate that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.