The package has a focused file tree, tests, release notes, and no install-time scripts. Its young project history, single active contributor, and lack of security scanning leave meaningful maintenance and oversight risk.
68%
Total Score
50
100
86
75
The package is only 42 days old with two releases, so its maintenance track record is still limited despite the recent release activity.
One contributor made all three recent commits, creating a concentrated maintenance dependency with no demonstrated handoff capacity.
There were three commits in the last three months, showing some activity, though the short history limits evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest oversight gap.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.