Usable with caveats: it is an actively published, organization-backed package with tests and a clear license, but its very young 0.x history and lack of recent recorded commit activity make long-term maintenance less certain.
68%
Total Score
83
100
75
90
The published artifact has no README, but the source repository has tests and the package is a library with substantial source coverage; the missing artifact README is a consumer-documentation gap rather than a maintenance failure.
Fourteen releases have been published over 116 days, including the assessed release today, showing active publishing. The short project history limits evidence of long-term durability.
No commits or active maintainers were recorded during the last three months. The same-day push and release show current activity, but the limited recent history still leaves maintenance continuity uncertain.
Composer is used as the build tool, but no security scanning tools were detected. This is a transparency and monitoring gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.2 | — | — |
cuyz/valinor Version ^2.4 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
thomas-institut/standard-api Version 1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.