The package is small and clearly scoped, with matching source files, an Apache-2.0 license, and no install-time scripts. Its very recent publication leaves maintenance capacity unproven, while the repository lacks security scanning and a security policy.
63%
Total Score
75
100
88
88
The package was first released 0 days ago and has four releases, all within the same day. This shows active initial publishing but provides no long-term maintenance history.
The repository records 0 commits and 0 active maintainers in the last 3 months. Because the package is only 0 days old, this is partly explained by its newness, but ongoing maintenance is not yet demonstrated.
Composer is used as a build tool, which supports reproducible project structure, but no security scanning tools were detected. This is a modest transparency and maintenance gap.
No security policy was found in the linked repository. This does not indicate a security defect, but it gives users little guidance for reporting issues in a new package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhp/core Version 802.0.* || 803.0.* || 804.0.* || 805.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.