Healthy and actively maintained, with solid documentation, tests, release notes, and recent repository activity. It is still a young pre-1.0 project maintained by one contributor, so expect breaking changes and some continuity risk.
78%
Total Score
75
100
88
80
The package declares post-install and post-update Composer scripts, which increase installation-time behavior and deserve review before adoption. No provided signal shows these scripts are dangerous.
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration represents a meaningful project-continuity risk.
One contributor made all 37 commits in the last three months, creating a real continuity risk for a young project with no demonstrated second maintainer.
The repository uses Composer build tooling, but no security-scanning tools were detected. This is a transparency gap, though the healthy workflow and code-review signals partly compensate for it.
No repository security policy was found, reducing clarity about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.