The repository is active and the package has a clear MIT license, a README, and no install-time scripts. Its short history, one-person publishing, concentrated commits, and absent security policy leave more maintenance risk than an established dependency.
67%
Total Score
75
100
79
75
The package is only 51 days old and has three releases, all published within minutes on the first day, so there is little evidence of sustained release maintenance.
One contributor made 19 of 21 recent commits, leaving maintenance heavily concentrated even though a second contributor is active.
Composer is used as a build tool, but no security-scanning tool was detected, so build support exists without an additional automated security check.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for adopters.
Version v0.1.3 is not a prerelease, but it remains before 1.0, so compatibility and API stability are not yet strongly established.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.