Apache-2.0 licensing, included tests, and organization-backed source provide a sound foundation. The missing security policy and security scanning reduce transparency, while the new project has not yet demonstrated sustained maintenance.
66%
Total Score
75
100
88
83
This package is 0 days old with only one release, so its maintenance record and release reliability are not yet established.
There were no commits and no active maintainers in the last 3 months. Because the package and repository are newly observed, this is limited evidence rather than proof of abandonment, but sustained maintenance is not demonstrated.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository-process gap.
The repository has no security policy, reducing clarity about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.0 | — | — |
psr/clock Version ^1.0.0 | — | — |
doctrine/dbal Version ~4.4.0 | — | — |
shopwell/core Version v6.7.0.0 | — | — |
async-aws/core Version ^1.22 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.