Clear licensing, documentation, and release notes make the artifact easy to understand. The repository is maintained by one person, with only one commit in three months and no security policy; pin this version if adopting.
68%
Total Score
50
100
94
75
The repository is owned by a user account, not an organization, so there is no observed organizational backing to compensate for the single-contributor maintenance model.
One contributor made all commits in the last three months, so maintenance depends entirely on a single person; the repository owner is an individual rather than an organization that could more readily hand work off.
Only one commit was made in the last three months, showing limited recent development activity; this is partly consistent with a release-focused artifact but still weak evidence of maintenance capacity.
The project uses Composer for builds but reports no security scanning tools, leaving a meaningful transparency and detection gap for an automated release artifact.
The repository has no security policy, reducing clarity about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.