The package is clearly scoped, licensed, tested, and has a minimal runtime dependency footprint. Its organization backing helps, but recent work is concentrated in one contributor and the repository has no security policy.
78%
Total Score
90
100
83
88
One contributor made all 14 commits in the last three months. Organization ownership provides some handoff capacity, but no second recently active contributor is shown, leaving a meaningful continuity concern.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but it does not outweigh the package's release and maintenance activity.
Composer is used for builds, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy. That leaves vulnerability-reporting and response expectations undocumented, reducing project transparency.
Version 0.1.54 is not a prerelease, although the package remains below 1.0 and may still have an evolving API.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.