Composer packaging is simple, and the three runtime dependencies are explicit. The project is very new, so its long-term maintenance capacity remains unproven.
62%
Total Score
50
100
71
83
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README reduces consumer transparency for a library.
The package has three releases, all published within about 7 hours, so release activity is visible but there is no meaningful long-term history yet.
No commits or active maintainers were recorded during the last 3 months; because the package is only hours old, this mainly leaves maintenance capacity unproven rather than demonstrating abandonment.
The repository name does not match the package name, and no README mention was available. This weakens confidence that the linked repository is clearly the package's canonical source.
Composer is used for the build, but no repository security-scanning tool was detected, leaving a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
niangpro/core Version self.version | — | — |
niangpro/http Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.