Clear licensing, a substantial README, and a matching repository improve transparency. The package is newly published, with no established commit history or security policy yet. Its dependency set and packaging appear straightforward.
68%
Total Score
50
100
88
83
All three releases were published on the same day, so this package has no demonstrated release history or long-term maintenance record yet.
There were no commits or active maintainers in the last three months. Because the package itself is newly published and the repository was pushed recently, this mainly shows that sustained maintenance is not yet proven.
Composer is used for builds, but no security-scanning tool was detected. That is a modest transparency gap for a package with server-side code.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sebastian/diff Version ^4.0 | — | — |
matthiasmullie/minify Version ^1.3 | — | — |
league/mime-type-detection Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.