The package is small but clearly documented, tested, licensed, and backed by a recent 1.0.1 release. Maintenance is concentrated in one contributor, and all three CI actions are unpinned, so ongoing reliability deserves attention.
72%
Total Score
50
100
88
75
The registry and repository are owned by the same individual account, so there is no organizational handoff capacity to offset the concentrated contributor base.
The package is young at 174 days, with two releases about 64 days apart. This shows some release activity but leaves limited long-term evidence.
One contributor made all commits in the last three months, concentrating maintenance responsibility and increasing continuity risk for this user-backed project.
There was one commit in the last three months, indicating some recent maintenance but a limited activity record.
Composer build tooling is present, but no security-scanning tool was detected; the missing scanner is a modest transparency gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.