The MIT license, focused dependency set, and detailed README make the package straightforward to evaluate and build. Security-policy coverage is limited, and the workflow uses two unpinned actions.
62%
Total Score
75
100
75
75
The package is only 154 days old and made eight releases, all within the last 12 months, but the latest release was about four months ago after a very compressed release burst. This supports early activity but leaves maintenance continuity uncertain.
The repository recorded zero commits and zero active maintainers in the last three months. For a package this new, that is a meaningful warning about ongoing maintenance capacity.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, though the package is young and popularity alone does not establish a health verdict.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanning adds a modest transparency and maintenance concern.
No security policy was found in the repository, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.