This release appears generally suitable to depend on: it is an actively published, stable-major package with 22 releases over 44 days, recent repository activity, clear licensing, substantial documentation and tests, and no deprecation or archival status. The main concerns are that the project is very young, all 71 recent commits came from one maintainer despite organization ownership, the repository has no security-scanning tooling or security policy, and two workflows request top-level write permissions. These issues warrant review for a production dependency, but the observed maintenance and transparency signals outweigh them.
78%
Total Score
88
100
83
80
The package is only 44 days old, which limits maturity evidence, but 22 releases in that period demonstrate active publication rather than abandonment.
All 71 recent commits came from one contributor, creating a meaningful continuity and review risk; organization ownership partly mitigates handoff risk but does not provide evidence of a second active maintainer.
The repository has only 1 star and no forks or watchers, indicating limited external adoption; this is supporting caution rather than a decisive health failure for a young package.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap for a package with native and capability-boundary code.
No repository security policy was found, reducing vulnerability-reporting transparency and incident-response visibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.