The release is well packaged, licensed, and backed by tests and a changelog. Its newly created repository has no observed commits yet, and no security policy is present.
64%
Total Score
50
100
79
75
The package is brand new: all 3 releases appeared on the same day, so there is not yet enough history to demonstrate sustained maintenance.
The repository recorded 0 commits and 0 active maintainers over the last 3 months. Because the repository itself is newly created, this is a maintenance warning rather than proof of abandonment.
The repository has 0 stars, forks, and watchers, providing no supporting evidence of community adoption. Popularity is only supporting evidence, so this modestly lowers confidence rather than deciding the result.
Composer is used for builds, but no security-scanning tools were detected. That is a transparency and hygiene gap, not a severe dependency risk by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2 | — | — |
psr/container Version ~1.1.2 || ~2.0.2 | — | — |
composer/semver Version ^3.4.0 | — | — |
wikimedia/assert Version ^0.5.1 | — | — |
wikimedia/wikipeg Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.