Usable with caveats: the release is clearly packaged, documented, tested, and backed by an active unarchived repository. However, it is only 3 days old with 9 releases, has no recorded commit activity over the past 3 months, and lacks security scanning and a security policy.
65%
Total Score
50
100
83
67
The registry namespace and repository owner match, but the owner is an individual rather than an organization, so there is limited evidence of institutional maintenance capacity.
The package is only 3 days old and has published 9 releases, with a median interval of about 5 hours, which indicates an immature and rapidly changing release history.
No commits or active maintainers were recorded in the past 3 months, which is concerning for maintenance evidence, although the repository's very recent creation and four merged pull requests provide some compensating activity.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not establish that a small package is unhealthy.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful verification gap for a package handling authentication and device secrets.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.