This release appears usable and reasonably transparent: it has a linked, non-archived repository, a strong README and changelog, repository tests, a clear MIT license, no install-time lifecycle scripts, frequent release activity, and no registry deprecation. The main concerns are that it is still pre-1.0, all three recent commits came from one contributor, the repository has no observed issue or pull-request activity, popularity is currently negligible, GitHub Actions lacks an explicit top-level token-permissions declaration, and no security-scanning tooling was detected. These factors make the project more dependent on a single maintainer and warrant monitoring before adopting it for critical workloads, but they do not indicate abandonment or an unfit release.
72%
Total Score
50
100
83
90
The repository is owned by an individual user rather than an organization, so there is no organizational backing to offset the concentrated maintainer and commit activity.
One contributor made 100% of the three commits in the last three months, creating a clear single-maintainer dependency and elevated continuity risk.
Only three commits were observed over the last three months, all from one active maintainer. Recent activity exists, but the low volume limits evidence of sustained maintenance capacity.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This may reflect a small or young project, but it provides little evidence of community review or maintenance participation.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but the absence of adoption signals reduces independent validation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
opis/json-schema Version ^2.6 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.