The project is only 50 days old and all recent commits come from one person, though organization backing and active releases help. It has no published security policy.
70%
Total Score
83
100
79
75
The package is 50 days old with five releases and a median interval of about 1 day, showing active early development but limited long-term history.
One contributor made all 14 recent commits, creating a real continuity risk; organization ownership provides some backing but does not remove the concentration.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest assurance gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
Version v0.5.0 is not yet at a stable major version, so its API and behavior may still change substantially.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.