The package is only hours old, with three releases and no established maintenance record. Its small library artifact has no README or tests, the repository has no security policy or scanning, and the repository does not clearly identify the package; the MIT declaration and lack of install scripts help.
58%
Total Score
100
75
83
The artifact contains no README, tests, or changelog, while the repository also reports no tests or changelog; missing tests and changelog are normal packaging practice, but the absent README is a real usability gap for a library.
The package is less than one day old and has only three releases, so there is not yet enough history to demonstrate sustained maintenance or maturity.
The repository name does not match the package name and its README does not confirm the package, so the source-package relationship is less transparent than it should be.
Composer is used as the build tool, but no security-scanning tool is present, leaving a modest transparency and maintenance gap.
The linked repository has no security policy, so there is no documented process for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
niangpro/core Version self.version | — | — |
niangpro/http Version self.version | — | — |
niangpro/cache Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.