The package has almost no release history, and the repository shows no commits or active maintainers in the last three months. Its organization backing, clear licensing, included tests in the repository, and lack of install scripts provide useful reassurance.
66%
Total Score
75
50
83
75
The release declares 31 runtime dependencies, which increases maintenance and compatibility complexity, but the signal provides no evidence that the dependencies are unsafe or unmanaged.
This is the first recorded release, published today, so there is not enough history to establish maturity or a dependable release pattern.
The repository records 0 commits and 0 active maintainers in the last three months, although its latest push is current; this leaves recent maintenance capacity unclear.
Composer is used for builds, but no security-scanning tooling was detected, leaving a maintenance and transparency gap for a package with a large dependency surface.
The repository has no security policy, so there is no documented route for reporting vulnerabilities or explaining the project's security process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0.0 | — | — |
lcobucci/jwt Version ^5.5 | — | — |
symfony/mime Version ~7.4.12 | — | — |
doctrine/dbal Version ~4.4.0 | — | — |
shopwell/core Version v6.7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.