Usable with caveats: the repository is active, correctly tied to the package, licensed, and backed by an organization, but this is a very young release with only one contributor and limited security transparency. Review its install-time scripts before adopting it.
67%
Total Score
75
100
81
70
The package runs post-install and post-update Composer scripts, which increase installation-time execution exposure and deserve review before use even though no maliciousness verdict is being made here.
The package is only 47 days old and has one release, so there is little release history from which to judge long-term maintenance or compatibility stability.
One contributor made all four recent commits, creating a genuine single-person continuity risk. Organization backing provides some mitigation, but no second active contributor is shown.
There were four commits in the last three months, showing recent work, but all activity came from one active maintainer, limiting demonstrated maintenance capacity.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected, leaving a modest transparency and preventive-maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.