The package is small and easy to audit, with a clear README, minimal runtime dependencies, and no install-time scripts. Its limited testing and security process leave more maintenance risk than a mature framework tool.
63%
Total Score
50
100
94
83
One contributor made 100% of the 4 recent commits. This concentration creates a meaningful continuity risk for a package intended to support framework tooling.
The repository had 4 commits in the last 3 months, so it is active, but only one maintainer contributed during that period.
Composer is used for builds, but no security scanning tools are present. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear, although this is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.