The package includes tests, a changelog, a substantial README, and no install-time scripts. Its pre-1.0 status, single active contributor, and lack of a security policy make long-term support less certain.
70%
Total Score
67
100
86
88
The repository is owned by a user account rather than an organization, so the concentrated contributor activity has no demonstrated organizational handoff support.
One contributor made all four recent commits, leaving maintenance highly concentrated and creating continuity risk.
Composer build tooling is present, but no security-scanning tool was detected, leaving a security-process gap.
The repository has no security policy, so users lack documented guidance for reporting and handling vulnerabilities.
The current v0.0.4 release is not a stable major version, so its API and behavior may still change substantially.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.