The package has a clear README, detailed documentation, a small runtime dependency footprint, and organization backing. Its security policy is absent, and the workflow references are not pinned, leaving important maintenance and build-reproducibility gaps.
62%
Total Score
75
100
81
75
This package is only 36 days old and has one release, so there is not enough release history to demonstrate sustained maintenance.
All recent commits came from one contributor, creating a concentrated maintenance dependency; organization backing partly reduces handoff risk but does not show a second active contributor.
Only one commit from one active maintainer was recorded in the last three months, providing weak evidence of ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest process gap.
No security policy was found, reducing transparency about vulnerability reporting and response procedures.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.