Usable with caveats: the repository is active, correctly linked, and organization-backed, but this is a very new one-release package with only one active contributor and limited documentation. Review its maturity and workflow permissions before making it a core dependency.
64%
Total Score
83
81
50
A README is present, but it is short and says the project is “coming soon,” leaving consumer guidance incomplete. The absence of packaged tests and a changelog is expected for a published artifact and is not a concern by itself.
This is a new package with one release, first published 44 days ago, so there is little release history to demonstrate stability or sustained maintenance.
All 18 recent commits came from one contributor, creating a real continuity risk. Organization backing provides some ability to hand off maintenance, but no second active contributor is evidenced.
Composer is used for builds, but no security scanning tooling was detected, which reduces automated supply-chain oversight.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.