Clear documentation and a correctly linked repository make this easier to evaluate and integrate. The small contributor footprint and lack of security-policy tooling leave maintenance and response practices unproven. Its native mobile scope also warrants checking compatibility with the stated platform requirements.
61%
Total Score
50
83
75
The repository is owned by an individual user rather than an organization, so the limited observed maintenance activity is not offset by visible organizational backing.
The package has only one release, published 150 days ago, so there is little release history from which to judge sustained maintenance. Its recent age partly explains the limited history but does not remove the uncertainty.
The repository recorded zero commits and zero active maintainers during the last three months. With only one release, this leaves maintenance capacity and abandonment risk materially unclear.
The repository has only 2 stars, no forks, and no watchers, providing little evidence of external review or community support. Low popularity is supporting evidence rather than a standalone failure.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and hygiene gap for a package handling secure storage.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.