Its dependency list is small and it has no install-time scripts. The source repository is active and unarchived, but the single-maintainer project has little supporting documentation or security process.
64%
Total Score
75
100
75
83
Only one registry account has publish access, which limits publishing redundancy. This is a modest concern rather than evidence of abandonment because the project is newly released and the repository was recently pushed.
The published artifact has no README, tests, or changelog. Missing tests and changelog are normal for a package artifact, but the absent README is a documentation gap for a library consumers must integrate.
The package is brand new, with three releases published within a few hours; this shows active initial work but provides little evidence of long-term maintenance or maturity.
The repository uses Composer build tooling, which fits the package ecosystem, but no security scanning tooling was detected; this is a small transparency and hygiene gap.
The repository has no security policy. For a new library this weakens the documented response path for vulnerabilities, although it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
niangpro/core Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.