The package includes focused tests, a simple dependency profile, and organization-backed source. Maintenance evidence is thin: it has only one release and no commits in the last three months, while security tooling and a security policy are absent.
62%
Total Score
75
100
75
88
The artifact contains tests and the repository also has tests, which supports basic maintainability. The missing README and changelog are transparency gaps for a library consumers must integrate, although the tests compensate for part of the documentation gap.
This is a young package, 144 days old, with only one release and no established release cadence. That limits evidence of long-term maintenance but is not severe for a newly published library.
There were zero commits and zero active maintainers in the last three months. Because the package has existed for only 144 days, this may reflect a completed small release, but it leaves limited evidence of ongoing maintenance.
Composer build tooling is present, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a hygiene weakness rather than evidence of abandonment.
The repository has no security policy. For a small client library this is a transparency gap, but it is not severe on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.