The package has a clear MIT license, tests, documentation, a matching source repository, and Composer-based build tooling. Its small, newly established project has no observed commit or issue activity yet, while security scanning and a security policy are absent.
58%
Total Score
83
100
81
75
Seven releases were published in less than 1 day, with a median interval of about 2.5 minutes. This shows active initial publishing but provides almost no long-term maintenance history.
No commits or active maintainers were observed over the preceding 3 months. Because the repository is less than 1 day old, this is evidence of an unproven maintenance track record rather than established abandonment.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene concern for a package intended for dependency use.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The assessed release is not a prerelease, but the latest version remains below 1.0 and the package has only just been established, so maturity is not yet demonstrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.4 | — | — |
colinodell/json5 Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.