The package has a clear MIT license, a matching repository, release notes, and no install-time scripts. It lacks tests and security scanning, while its small maintainer base and immature 0.x history leave limited evidence of long-term reliability.
60%
Total Score
50
100
79
67
Only one registry publishing account is listed. The linked repository is user-owned rather than organization-owned, so there is no provided project-backing evidence to offset this concentration.
The repository owner is an individual user, so the available ownership data does not show organizational backing that would compensate for concentrated maintenance.
The package is only 5 days old, despite four releases in that period; this shows active initial development but provides little evidence of sustained maintenance or maturity.
All three recent commits came from one contributor, leaving no demonstrated handoff capacity for this user-owned project.
Three commits from one active maintainer in the last 3 months show current activity, but the small volume gives limited evidence of an established maintenance process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version 4.9.* | — | — |
vlucas/phpdotenv Version 5.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.