The package has clear documentation, a matching license, stable releases, and no install-time scripts. Maintenance capacity is narrow, with one recent contributor and no security policy or scanning evidence.
68%
Total Score
50
100
94
83
Only one account has registry publish access. The linked repository is user-owned rather than organization-owned, so there is no provided backing evidence to offset this narrow publishing base.
One contributor made all commits in the last 3 months, giving the project a single-person maintenance base. The active recent release helps, but no second active contributor is shown.
The repository had one commit in the last 3 months, showing some recent activity but limited maintenance capacity. The recent release partly offsets the low volume, but activity remains thin.
Composer build tooling is present, but no security scanning tools were detected. For a library handling online validation requests, this is a modest transparency and maintenance gap.
The repository has no security policy. This makes vulnerability reporting and coordinated maintenance less clear for consumers.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.