Releases arrived roughly every 23 days, and the package declares a license with a useful README. The available project evidence provides limited reassurance about ongoing review and operational ownership.
58%
Total Score
50
79
75
The source repository is owned by an individual account rather than an organization, providing less visible institutional backing for a package with no recent commit activity.
No commits and no active maintainers were recorded in the last three months, which weakens evidence of continuing maintenance despite the recent release history.
The repository name does not match the package name and its README does not mention the package, so the link between the artifact and source is not clearly established.
Composer is used as the build tool, but no security-scanning tooling was detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency about how vulnerability reports would be handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.