The MIT declaration, focused package contents, and minimal runtime dependency make the package easy to inspect and integrate. Its limited project backing and absent security policy leave less evidence of long-term maintenance than mature alternatives.
62%
Total Score
50
100
83
83
The package is backed by an individual repository owner rather than an organization, so the short one-release history provides limited evidence of sustained maintenance capacity.
This is a 152-day-old package with only one release and no established release cadence, so its maintenance track record remains unproven.
There were zero commits and zero active maintainers in the three months before collection. For a platform plugin, that is meaningful evidence that ongoing maintenance capacity is uncertain.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption signal to offset the limited activity history.
Composer is used for builds, but no security scanning tool was detected. The missing scanner is a modest repository hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.