Usable with caveats: it is clearly packaged, licensed, dependency-light, and backed by a matching organization repository with tests. However, this is a brand-new v0.1.0 release with no demonstrated commit history, adoption, or security policy, so its maintenance maturity is unproven.
68%
Total Score
83
100
78
90
The package was published today and has only one release, so there is no release track record from which to judge long-term maintenance.
There were zero commits and zero active maintainers in the measured three-month window. Because the repository was created and pushed today, this mainly shows that maintenance history is unproven rather than that activity has collapsed.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for a new package, but not by itself a reason to reject a small specialized library.
Composer build tooling is present, but no security scanning tool is configured. The missing scanner is a transparency gap, although the package has no lifecycle scripts and no workflows.
No security policy is provided, leaving vulnerability-reporting expectations unclear for dependents.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.