The project is only 65 days old and nearly all recent commits come from one contributor. It has tests, a substantial README, an explicit MIT license, and recent activity, but workflow references are unpinned and no security policy or scanning is reported.
68%
Total Score
70
100
89
75
One registry maintainer is consistent with the linked repository being owned by an individual, but it provides limited publishing redundancy.
The repository is owned by an individual rather than an organization, so the concentrated contributor activity has no demonstrated organizational handoff capacity to offset it.
This is a young package, 65 days old, with only one release. That leaves little evidence of long-term release consistency or maturity.
One contributor made 59 of 60 recent commits, leaving maintenance highly concentrated despite a second contributor being present.
Composer is used for builds, but no security-scanning tooling is reported, leaving security-quality checks less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
adhocore/jwt Version ^1.1.3 | — | — |
eftec/bladeone Version ^4.13 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
pecee/simple-router Version dev-master | — | — |
webonyx/graphql-php Version ^15.34 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.