Documentation, licensing, and repository activity are solid, with release notes for this version and two active contributors. Install-time scripts and a concentrated maintainer base add practical review points for a young project.
68%
Total Score
63
100
88
83
The package runs post-install and post-update Composer scripts. These add supply-chain and reproducibility review points even though no other provided signal shows malicious behavior.
The registry has one publishing maintainer. The linked repository is user-owned rather than organization-owned, so there is limited visible publishing redundancy, though repository activity shows another contributor.
The package and repository are consistently owned by the same individual, and the repository is user-owned. This supports identity consistency but provides less organizational maintenance backing.
The package is only 60 days old and has two releases, both published within roughly 5 hours, so there is limited evidence of sustained release maintenance.
Two contributors were active, but the top contributor made about 65% of recent commits. That is a modest concentration risk for a user-owned project, not a severe single-maintainer failure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.