The repository has no security scanning or security policy, leaving limited evidence about ongoing safeguards. The package is clearly identified, licensed under MIT, documented, and has a focused runtime dependency profile.
62%
Total Score
100
79
75
This release is the package's only release, published 104 days ago, so there is not yet enough history to demonstrate sustained maintenance or responsiveness.
Composer is used for builds, but no security scanning tools are present; this is a modest transparency and maintenance gap for a package that runs a CLI subprocess.
The repository has no security policy, so reporting and response expectations are not documented. This is a hygiene gap rather than evidence of unsafe behavior.
The package is at v0.125.0 but is not on a stable major version, which adds some compatibility uncertainty for adopters despite it not being marked prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.