The package has clear usage instructions and a small, explicit runtime dependency set. Its project is very young and all recent commits come from one contributor, while no security policy is published. Pin this exact version until it demonstrates broader maintenance.
61%
Total Score
50
100
86
83
The package is only 58 days old and has one release, so there is little evidence of sustained release maturity. Its recent publication means this is an early-stage concern rather than evidence of abandonment.
One contributor made all three recent commits, concentrating maintenance responsibility entirely in one person. The repository owner is an individual rather than an organization, so no provided backing signal offsets that concentration.
Three commits were made in the last three months, which shows some recent activity for a package only 58 days old. The limited volume leaves maintenance depth uncertain.
Composer is used for the build, providing basic project tooling, but no security-scanning tool was detected. For a young package, the missing scanning coverage is a modest transparency and maintenance concern.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.