The package includes tests, a README, a changelog in its repository, and a clear MIT license. Organization backing and recent commits help, but the project is only 53 days old, all recent commits come from one contributor, and no security policy or scanning is present.
67%
Total Score
83
100
81
75
The package is only 53 days old, despite 12 releases in that period; releases arrived about every 14 hours, showing activity but little long-term maintenance evidence.
One contributor made all nine commits in the last three months, leaving no demonstrated backup maintainer and increasing continuity risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented reporting or response process for vulnerabilities.
v4.0.0 is a stable major release, which is positive, but half of recent releases were prereleases, adding some uncertainty for a very young package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^3.0 | — | — |
quioteframework/quiote Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.