Documentation is effectively empty, and all recent work comes from one contributor. The license, tests, active repository, and package/repository name match provide useful support, but the project is still too young for strong confidence.
62%
Total Score
67
81
83
The artifact and repository include tests, but the package README has zero content and there is no changelog. An empty README is a real documentation gap for a library consumers must integrate.
The repository is owned by the same individual namespace as the package and is user-owned, so there is no organizational backing to offset the concentrated contributor base.
This is the package's only release, published about 2 months ago, so there is little evidence of release maturity or long-term maintenance.
All 15 recent commits came from one contributor, leaving maintenance dependent on a single person and increasing continuity risk.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap, not evidence of a security failure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.