Usable with caveats: the package is licensed, documented, tested, and not deprecated or archived, but it is very new and has had no commits or maintainer activity for about seven months. Its zero-star repository and lack of security policy add uncertainty for a production dependency.
55%
Total Score
50
100
72
90
There were zero commits and zero active maintainers during the last three months, despite the package being only about 204 days old; this materially increases abandonment risk.
This package is only about 204 days old and has just two releases, both published within minutes on its first day, so there is limited evidence of sustained release maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption signal for this very new package.
Composer is used as build tooling, but no security scanning tools are configured, leaving automated security coverage unsubstantiated.
The linked repository is not archived, but its last push was about seven months ago, which is consistent with the inactivity shown by the commit signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.