Usable with caveats: the package is actively developed, licensed, backed by an organization, and has a small dependency surface. It is very new, all recent commits come from one contributor, and the repository lacks a security policy while granting workflow write access.
68%
Total Score
88
100
83
80
This package is only 50 days old and has one release, so there is little release history from which to judge long-term stability or responsiveness.
All 46 recent commits came from one contributor, creating a meaningful continuity risk if that person becomes unavailable. Organization backing provides some handoff capacity but does not remove the concentration.
The repository has no stars, forks, or watchers. For a new organization-backed package this is limited supporting evidence rather than a standalone health verdict.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning is a transparency gap, though it is not by itself evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.