Usable with caveats: it is a small, clearly packaged, licensed release with recent publishing and an active organization-owned repository. However, the project is only 43 days old, has just two commits in three months from one contributor, and lacks security scanning and a security policy.
72%
Total Score
75
100
88
90
The package is very young at 43 days old, with three releases and a median interval of about 21 days; this shows recent activity but not yet long-term maintenance maturity.
One contributor made all two commits in the last three months, creating concentration risk. The organization-owned repository provides some ability to hand maintenance off, so this is a caution rather than a severe risk.
Only two commits were recorded in the last three months, with one active maintainer. Recent release activity helps, but the observed development pace is thin.
Composer is used for builds, but no security scanning tools are configured, leaving a real repository-hygiene gap for a package handling Firebase authentication and cloud calls.
No SECURITY.md or equivalent security policy was found, leaving vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.