The package has a clear README, a small runtime dependency set, and recent source activity. Its lack of a security policy leaves a modest transparency gap for long-term maintenance.
68%
Total Score
75
100
83
50
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. This creates a material licensing concern for a dependency presented as open source.
One contributor made all 5 commits in the last 3 months, so maintenance depends entirely on one person. The active contributor offsets abandonment concerns partially but does not remove the continuity risk.
The repository has no stars or forks and one watcher, indicating limited visible adoption. Popularity is supporting evidence only, so this modestly limits maturity confidence without determining the verdict.
Composer is used for builds, which fits the package ecosystem, but no security-scanning tooling was detected. For this small package, that is a modest hygiene gap rather than a severe risk.
The repository has no security policy. This reduces transparency about vulnerability reporting and handling, although the package's small scope and active maintenance provide some compensation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.