The focused dependency set, README, tests, and matching Apache-2.0 license support adoption. Security coverage is limited, and the project has little public traction.
62%
Total Score
50
100
83
67
The repository is owned by an individual user rather than an organization, so the small registry maintainer context is not offset by visible organizational backing.
The package has only two releases, both published within about one day, and no release activity for 136 days. That is limited evidence of sustained maintenance for a relatively new package.
There were zero commits and zero active maintainers in the last three months, with the last push coinciding with the initial release period. This materially raises abandonment risk.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this reinforces the limited external validation alongside the lack of recent commits.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.