The package has a clear README, a matching source repository, and an MIT license. Its single-maintainer base and lack of security scanning add modest concern.
56%
Total Score
50
100
88
83
One registry maintainer is responsible for publishing the package. This is workable for a small project but leaves limited visible publishing redundancy.
The registry namespace and repository are owned by the same individual account, showing consistent ownership but no organizational backing or larger maintenance structure.
This is the only release, published 695 days after the assessment period began, with no releases in the last 12 months. That indicates limited ongoing maintenance.
There were zero commits and zero active maintainers during the last three months, consistent with an effectively inactive project and increasing abandonment risk.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.