The package includes a clear README, tests in the repository, release notes, and a valid MIT license. Maintenance is concentrated in one contributor, with only two commits in three months; workflow action references are also unpinned.
78%
Total Score
50
100
94
83
Only one registry account has publish access. This is a modest resilience concern for a user-owned project, although repository activity and recent releases show that the maintainer is currently active.
The registry namespace and repository are owned by the same individual user, so there is no organization backing to offset the concentrated maintainer base.
All two recent commits came from one contributor, so maintenance could be disrupted if that contributor becomes unavailable.
The repository received two commits in the last three months from one active maintainer, showing recent activity but a relatively light maintenance pace.
Composer build tooling is present, but no security-scanning tool was detected. For this small package this is a minor transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
codeat3/blade-phosphor-icons Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.