Usable with caveats: this is a very young package with only 35 days of history and all seven recent commits from one contributor. Organization backing, active releases, a matching repository, and clear source documentation provide some confidence, but tests and security policy are absent.
72%
Total Score
83
100
72
90
A substantial README is present, but neither the package nor repository contains tests or a changelog. The documentation helps explain this specialized native extension, but the missing tests still reduce confidence in maintenance quality.
The package is only 35 days old, with four releases and a median interval of 1.1 days, so it shows active initial development but little long-term maintenance history.
All seven recent commits came from one contributor, creating a real continuity risk; the organization-owned repository provides some compensation because maintenance can potentially be handed off internally.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity alone does not determine whether a small specialized package is healthy.
Composer build tooling is present, but no security scanning tools are configured. Build support is positive, while the missing scanning capability leaves a security-hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.