Usable with caveats: the release is well documented, licensed, tested, and not deprecated, but it is brand new with only two releases and no demonstrated historical commit activity. Treat it as an early-stage dependency until its maintenance record develops.
58%
Total Score
75
100
78
80
Only two releases exist and the package is less than one day old, so there is very little evidence of sustained maintenance or release stability.
No commits or active maintainers were recorded in the past three months, leaving no demonstrated maintenance track record; the very recent repository creation limits how strongly this indicates abandonment.
The repository has zero stars, forks, and watchers. Given that the project is less than one day old, this is weak maturity evidence rather than a standalone severe concern.
The repository uses Composer and just for build tasks, but it has no security scanning tool, leaving a modest security-process gap.
No repository security policy is present, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.