Healthy and usable, with the usual caution for a very new 0.0.x release. It has active two-person maintenance, tests, release notes, clear documentation, and organization backing; the main gaps are limited release history and missing security-policy and scanning evidence.
78%
Total Score
100
100
81
80
This is a new package, only 71 days old with one release and no established release cadence. That limits evidence of long-term maintenance and compatibility stability.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability reporting and response expectations undocumented.
One workflow has top-level write permissions, but all analyzed workflows declare permissions and one is read-only. The write-enabled release automation warrants review, while the explicit declarations provide some control.
Version v0.0.1 is an early 0.x release rather than a stable major release, so its API and behavior may still change substantially.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
open-feature/sdk Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.