Its MIT licensing and matching organization-backed repository provide useful transparency. The project is too new to demonstrate sustained maintenance, and the 17-character README gives consumers little guidance.
61%
Total Score
75
75
75
A README is present, but it contains only 17 characters and offers virtually no integration guidance. Missing tests and a changelog in the published artifact are expected packaging practice.
The package is 0 days old with four releases published within hours, so there is not enough history to demonstrate a reliable maintenance pattern.
There were no commits or active maintainers in the past three months; because the repository and package are newly created, this is limited evidence rather than proof of abandonment.
Composer build tooling is present, which supports reproducible project structure, but no security scanning tooling is configured, leaving a modest transparency gap.
The repository has no security policy, reducing the visibility of vulnerability-reporting and response practices for a package intended for dependency use.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.