The repository is small and entirely maintained by one contributor, while four commits in the last three months show recent activity. Organization backing, matching licensing, and no install scripts reduce adoption risk, but the project has no tests or security policy.
68%
Total Score
75
81
75
One registry maintainer is consistent with the organization-backed project, but it leaves little visible publishing redundancy.
The package includes a README, while the absence of tests and a changelog is normal packaging practice and is not penalized; the repository also reports no tests or changelog.
This is a young package with one release over 38 days and no established release cadence, so its long-term maintenance is not yet demonstrated.
All four recent commits came from one contributor, creating a meaningful continuity risk; organization backing provides some ability to hand maintenance off.
Composer is used as a build tool, but no security scanning tools are reported, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.