The package includes tests, a clear README, and security scanning. Organization backing helps offset the single-contributor activity, but its very short history leaves durability unproven.
64%
Total Score
67
94
83
The package is newly published, with only two releases and no established release interval, so maintenance durability is not yet demonstrated.
All recent commits came from one contributor, creating concentration risk; organization ownership provides some ability to hand maintenance to others.
Two commits in the last three months show some activity, but the small volume provides only limited evidence of sustained maintenance.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a package with application-facing functionality.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^8.1 | — | — |
doctrine/dbal Version ^4 | — | — |
survos/kit-bundle Version ^2.28 | — | — |
survos/ftm-resolver Version ^2.31 | — | — |
survos/jsonl-bundle Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.