Clear licensing, tests, and a security policy provide useful project hygiene. The package is still new, has only one release, no commits in the last three months, and uses two unpinned workflow actions.
62%
Total Score
50
50
86
75
Thirty runtime dependencies create a broad dependency surface for a package that supplies framework tooling, increasing maintenance and update exposure.
The repository is owned by a user account rather than an organization, so the single registry maintainer does not benefit from clear organizational backing.
This is a young package, 106 days old, with only one release and no established release cadence, so its maturity remains unproven.
The repository recorded zero commits and zero active maintainers over the last three months; for a package only 106 days old, this leaves maintenance continuity uncertain rather than proving abandonment.
Composer is used for builds, but no security scanning tool was detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
switon/db Version ^1.0 | — | — |
switon/di Version ^1.0 | — | — |
switon/cli Version ^1.0 | — | — |
switon/jwt Version ^1.0 | — | — |
switon/log Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.