The package includes a clear README, changelog, repository tests, and a permissive MIT license. Its small dependency surface and recent repository activity are reassuring, but operational security hygiene remains limited.
68%
Total Score
63
100
81
83
Only one registry account has publish access. The matching user-owned repository makes this understandable, but it leaves limited publishing redundancy.
The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor concentration is not offset by visible organizational handoff capacity.
The package is only 51 days old and made seven releases in roughly one day, with median intervals of about 27 minutes. This indicates active initial development but limited evidence of long-term release discipline.
One contributor made all 10 commits in the past three months, so maintenance depends entirely on a single person and has a meaningful continuity risk.
The project uses Composer and Make, but no security scanning tools were detected, leaving security-focused maintenance less visible.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.