The repository is small and has no security policy or automated security scanning. A matching source repository, clear MIT licensing, stable versioning, and release notes provide useful transparency, but maintenance evidence remains thin.
56%
Total Score
50
100
83
75
The repository is owned by an individual account rather than an organization. This does not prove weak backing, but it offers less visible institutional continuity than organization ownership.
The package is about three years old with four releases, one in the last 12 months, and a typical gap of about 11 months between releases. This supports continued publication but indicates a slow maintenance cadence.
There were no commits and no active maintainers in the past three months. Although the repository was recently pushed for the release, the lack of recent development activity is a meaningful maintenance concern.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide little independent evidence of community adoption or review.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.