Usable with caveats: this is a five-day-old v0.1.0 package with only one release, so its long-term stability is unproven. The organization-backed repository is active and well-scaffolded, but it lacks a security policy and automated security scanning.
68%
Total Score
88
100
81
90
The package is only 5 days old and has one release, so there is not enough history to establish sustained maintenance or release stability.
One contributor made 6 of 7 recent commits, creating concentration risk; however, the repository is organization-owned and a second contributor remains active, which provides some handoff capacity.
Composer build tooling is present, but no security scanning tools are configured, leaving a genuine supply-chain hygiene gap.
The repository has no security policy, so users lack a stated process for reporting and handling vulnerabilities.
The latest release is v0.1.0 rather than a stable major version, which signals an early API and maturity stage.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.