The package has clear documentation, tests, a changelog, a small dependency surface, and an active organization-owned repository. Recent repository activity is quiet, and the MIT declaration differs from the Apache-2.0 license detected in the artifact.
68%
Total Score
83
100
88
88
The manifest declares MIT, while the artifact license file is recognized as Apache-2.0; although a license file exists, the mismatch creates a transparency concern.
The repository shows zero commits and zero active maintainers in the last 3 months. This is partly offset by a release published on the assessment date, but the recent development signal remains thin.
Composer build tooling is present, but no security-scanning tooling is reported. The missing scanner is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for consumers.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.