The MIT license, stable versioning, and organization-owned repository provide a useful baseline. Documentation is minimal, and the project shows limited ongoing activity for a package first released about one year ago.
58%
Total Score
83
81
83
A README is present and the exact release has a GitHub release, but the README is only 6 characters long and offers little consumer guidance. Missing tests and a changelog in the package are normal packaging practice.
The package has had only one release, with no releases in the past 12 months, limiting evidence of continued maintenance.
The repository recorded no commits and no active maintainers in the past three months, which weakens evidence of ongoing maintenance.
The repository uses Composer, but no security scanning tool was detected; the missing scanning is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.