The MIT license, focused dependencies, and organization-owned matching repository support straightforward adoption. Missing tests, README, security policy, and scanning leave less evidence for long-term support.
55%
Total Score
75
100
71
50
No README is present in the published package or repository, which makes library integration less transparent. The absent tests and changelog are normal packaging omissions and are not treated as separate gaps.
The package has only 3 releases over about 3 years 9 months, with a median interval of about 19 months and just 1 release in the last 12 months. The recent release provides some activity, but the long gaps weaken maintenance confidence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The release-day push partly offsets this, but there is little continuing activity evidence beyond the release itself.
Composer build tooling is present, but no security-scanning tool was detected. That is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This reduces transparency for a package intended to be used as a dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.2 | — | — |
micro/kernel Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.