Recent releases and a matching, clearly documented artifact support continued maintenance. Composer tooling and automated security scanning help offset the lack of a security policy and narrow contributor base.
76%
Total Score
67
100
100
83
The repository is owned by the same individual namespace as the package, so the package identity is clear, but there is no organization backing to offset the single-maintainer concentration.
All two recent commits came from one contributor, leaving maintenance dependent on a single active person and creating a meaningful continuity risk.
No repository security policy was found, which limits guidance for reporting vulnerabilities, although automated security scanning provides partial compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.