Documentation, release notes, and licensing are clear, and installation has no lifecycle scripts. The dependency set is broad, while no security policy is provided.
64%
Total Score
67
50
79
75
The package declares 30 runtime dependencies and no development dependencies, creating a broad runtime dependency surface for an early release and increasing upgrade and compatibility exposure.
The repository is owned by a user account rather than an organization, so the single-contributor concentration represents a genuine maintenance-capacity concern.
The package is 0 days old with only 2 releases, so there is not yet enough history to demonstrate sustained maintenance or compatibility stability.
One contributor made 100% of the 73 commits in the last 3 months, leaving little demonstrated handoff capacity for a user-owned project.
Composer is used for builds, but no security scanning tools are present, leaving an unaddressed repository security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.20 | — | — |
nelexa/zip Version ^4.0 | — | — |
ramsey/uuid Version ^4.0 | — | — |
tinywan/jwt Version ^1.11 | — | — |
webman/cache Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.