This is a very new, early-stage release with only one published version, so its long-term maintenance and stability are not yet demonstrated. The package is nevertheless licensed, small in scope, has a README and tests in both the artifact and repository, declares a minimal dependency profile, has no install-time scripts, is not deprecated or archived, and its repository explicitly explains the mirror and package relationship. The absence of security tooling and a security policy leaves transparency and assurance gaps, but the available evidence does not indicate that the package is currently unfit to adopt; depend on it cautiously and reassess after a history of releases and maintenance develops.
68%
Total Score
50
100
83
90
The package is only 1 day old and has a single release, so there is not yet enough release history to establish maintenance continuity or maturity.
There were no commits and no active maintainers in the last 3 months, but this is consistent with the package being only 1 day old; it still leaves ongoing maintenance unproven.
Composer build tooling is present, but no security scanning tools are configured, leaving a genuine repository assurance gap.
The repository has no security policy, reducing transparency around vulnerability reporting and response expectations.
The current version is v0.1.0 rather than a stable major release, which indicates an early API and maturity stage even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.