Usable with caveats: the release is clearly licensed, tested, documented, and has a clean package structure, but it is brand new with no demonstrated maintenance history. Review future activity before making it a long-term dependency.
65%
Total Score
50
100
81
80
The registry namespace and repository are owned by the same individual, giving the package direct ownership alignment, though there is no organization backing to broaden maintenance capacity.
This is the first release and the package is only hours old, so there is no track record of maintenance, compatibility, or responsive fixes yet.
There have been no commits in the measured three-month window and no active maintainers recorded; because the project is brand new, this mainly reflects insufficient history rather than proven abandonment.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and monitoring gap.
The repository has no security policy, which leaves vulnerability reporting and response expectations undocumented for consumers.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.