Clear documentation, release notes, organization backing, and a small runtime dependency surface improve its initial transparency. The license mismatch, absent security policy, and entirely unpinned workflow actions leave important trust and maintenance gaps for a new pre-1.0 release.
63%
Total Score
100
100
71
75
The manifest declares BUSL-1.1 while the artifact license file is detected as Apache-2.0; the mismatch creates legal and provenance ambiguity despite both the artifact and repository containing license files.
This is the package's first release, published today, so there is no release track record yet. That limits evidence of maintenance maturity but does not indicate abandonment by itself.
Composer build tooling is present, but no security-scanning tooling was detected. That is a modest transparency and maintenance gap for a package that integrates into application request handling.
The repository has no security policy. For a package that can apply server-side fixes and alter application request behavior, the absence of published vulnerability-reporting guidance is a meaningful transparency gap.
Version v0.2.0 is pre-1.0, so its API and behavior may still change. It is not marked as a prerelease, which partly offsets the stability concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.