Clear licensing, a matching repository, and documented release notes improve transparency. The single-maintainer project is only four days old, and its 25 runtime dependencies plus no security policy leave limited evidence of long-term resilience.
62%
Total Score
83
50
83
75
The package declares 25 runtime dependencies and no development dependencies. This broad runtime surface increases upgrade and transitive-maintenance burden, with no provided evidence that it is minimized or tested.
The package is only 4 days old, with 8 releases clustered over that period. This shows active publishing but provides little evidence of sustained maintenance or release stability.
One contributor made all 7 commits in the last 3 months, leaving the project dependent on a single maintainer. The repository owner is an individual rather than an organization, so there is no provided backing signal to compensate for that concentration.
The repository has no security policy. For a backend package with many runtime dependencies, this leaves vulnerability reporting and response expectations unclear.
Version 0.1.7 is not a prerelease, but the package remains below 1.0 and has no established history. Consumers should expect the API and behavior to remain relatively immature.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.0 | — | — |
tinywan/jwt Version ^1.11 | — | — |
webman/cache Version ^2.1 | — | — |
webman/event Version ^1.0 | — | — |
webman/redis Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.