The project has only one release and no commits in the last three months, so its maintenance track record is still unproven. MIT licensing, a matching repository, tests, documentation, and organizational backing provide useful transparency.
62%
Total Score
75
100
88
75
A post-create-project-cmd install-time script is present, adding execution during project creation and warranting caution even though no malicious conclusion follows from this signal.
The package is 109 days old and has only one release, leaving little evidence of sustained maintenance or release discipline.
There were zero commits and zero active maintainers in the last three months. For a package this young, that leaves future maintenance capacity unproven rather than demonstrating abandonment.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest repository hygiene gap.
No GitHub Actions workflows were present, so no workflow-specific trigger, permission, or action-pinning risk was found; this also means there is no observed CI automation to support ongoing validation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.