The package includes tests, a useful README, and no install-time scripts. Its small dependency set keeps integration straightforward, but pinning this early-stage release is prudent.
62%
Total Score
50
100
75
83
The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor concentration is not compensated by visible organizational handoff capacity.
The package is 400 days old with only three releases and two releases in the last 12 months; a median interval of about 168 days indicates a slow maintenance cadence.
One contributor made all commits in the last three months, leaving maintenance dependent on a single active person without organizational backing shown by the provided project context.
Only one commit was recorded in the last three months, indicating limited recent development activity even though it is not absent.
Composer is used for builds, but no security scanning tool is present, leaving a modest transparency and maintenance gap for a package handling Firebase credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/http-client Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.