The repository has tests, release notes, minimal runtime dependencies, and clean workflow permissions. Maintenance is concentrated in one contributor, and no security policy or scanning is present.
72%
Total Score
67
100
79
75
The repository is owned by a user rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
The package is only 52 days old with three releases, released about every 11 days; this shows active early development but not long-term stability.
One contributor made all 31 commits in the last three months, creating a substantial single-maintainer continuity risk.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency and assurance gap.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.