The package has a clear MIT license, a usable README, tests, security policy, and a repository that matches the package. Its broad dependency footprint and unpinned workflow actions add modest maintenance and build risks; pin v1.0.0 until follow-up releases demonstrate sustained activity.
62%
Total Score
50
50
83
100
Twelve runtime dependencies create a relatively broad dependency surface for a first release, increasing upgrade and compatibility work, though the dependencies fit the framework-oriented package structure.
This is a new package released 105 days ago with only one release, so there is not yet enough release history to establish durable maintenance.
There were zero commits and zero active maintainers in the last three months, with the last push occurring on the initial release date; ongoing maintenance is therefore unproven.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but the package is only 105 days old, so it is not decisive by itself.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
switon/db Version ^1.0 | — | — |
switon/di Version ^1.0 | — | — |
switon/id Version ^1.0 | — | — |
switon/core Version ^1.0 | — | — |
switon/event Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.