The small, focused package has clear documentation, tests, minimal dependencies, and organization backing. Its long release gaps and limited repository safeguards leave more maintenance uncertainty than a mature dependency should.
66%
Total Score
75
100
81
83
The package has existed since 2016 and released once in the last 12 months, but its median release interval is about 768 days, indicating a slow maintenance cadence.
There were no commits and no active maintainers in the three months before collection. The recent release shows some current activity, but does not remove the concern about a thin ongoing development signal.
The repository name does not exactly match securetrading/data and its README does not mention the package. This may be a subpackage naming difference, but the lack of either linkage signal warrants caution about source-package correspondence.
Composer is used for builds, but no security scanning tool is configured, leaving automated detection coverage unclear.
The repository has no security policy, so its process for receiving and disclosing vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.