The Apache-2.0 license, matching organization-backed repository, and straightforward Composer dependency are reassuring. Its release and maintenance record are too new to establish long-term reliability, so pin this version and watch subsequent releases.
70%
Total Score
75
100
88
88
This is the package's first release, published 0 days ago, with only 1 release overall; there is not yet enough history to demonstrate sustained maintenance.
The repository shows 0 commits and 0 active maintainers in the last 3 months. Because the package is only 0 days old, this is primarily a lack of maintenance track record rather than proof of abandonment.
Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tool is configured; this is a modest transparency gap for supply-chain maintenance.
The linked repository has no security policy. For a tiny generated type-definition package this is a minor gap, but it provides no documented vulnerability-reporting path.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/async-aws-core-impl Version ~1.30.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.