The project has clear documentation, repository tests, a license, and a recent release. Its single active contributor and one commit in the last three months leave limited backup if maintenance stops. Workflow actions are unpinned, adding a modest reproducibility concern.
68%
Total Score
50
100
94
67
Only one account has registry publishing access. Because the repository is user-owned rather than organization-owned, this reflects a genuine concentration of publishing responsibility.
One contributor made 100% of the one commit in the last three months. With user ownership and no second active contributor shown, maintenance depends heavily on one person.
The repository recorded only one commit in the last three months. A recent release partly offsets this, but the observed development pace is still thin.
Composer is used as a build tool, but no security-scanning tool was detected. This is a modest transparency and assurance gap, not evidence of unsafe code.
The repository has no security policy. That leaves vulnerability reporting and maintainer response expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.