The package has clear documentation, release notes, a license, and no install-time scripts. A security policy helps, but the repository reports no security scanning and limited project activity beyond the initial release.
67%
Total Score
67
100
88
100
The repository is owned by an individual user rather than an organization, so the single-person activity concentration is not offset by visible organizational backing.
This is a 49-day-old package with only one release, so there is little evidence of a sustained release track or long-term maintenance.
All four recent commits came from one contributor, leaving maintenance dependent on a single active person and creating continuity risk.
Composer is used for builds, which is appropriate, but no security scanning tools were detected. That is a modest transparency and maintenance gap, not a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.