The package has a clear Apache-2.0 license, a linked non-archived repository, and no install-time scripts. Its maintenance record is unproven, and the repository README does not identify this package, which weakens confidence in the source link.
62%
Total Score
50
79
75
This is the first release and was published less than one day ago, so there is no release track record yet. That is a maturity gap rather than evidence of abandonment.
There were no commits or active maintainers in the preceding three months, but the repository and release are both less than one day old, so this mainly reflects insufficient history.
The repository name does not match the package name and its README does not mention the package, so the linkage is less convincing even though the repository owner matches the registry maintainer.
Composer is used as the build tool, which fits the Packagist package, but no security scanning tooling is present. The missing scanner is a modest hygiene gap, not a standalone dependency blocker.
The repository has no security policy. For a library involved in signing PDF documents with an electronic identity, that reduces transparency for reporting and handling security issues.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.