The license is explicit, and the package includes a substantial README and release notes. No security policy or automated security scanning leaves the project’s maintenance and security practices less transparent.
57%
Total Score
50
79
67
The artifact and repository each contain only LICENCE, README.md, and composer.json, indicating a documentation or pre-sales listing rather than inspectable module source. This limits transparency for a dependency.
This is a young package with only one release, published about 99 days ago, so there is not yet enough history to demonstrate sustained maintenance.
The repository recorded no commits and no active maintainers in the last three months. That is concerning for a package whose registry history also contains only one release.
The linked repository name does not match the package name and its README does not mention the package, so the repository’s relationship to this release is not independently clear.
Composer build tooling is present, but no security scanning tools were detected. This is a modest process gap rather than evidence of an unsafe release by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.