The package is narrowly scoped and its organization-backed repository matches the published package. Apache-2.0 licensing, a direct implementation dependency, and no install scripts are reassuring, but its single-release history and absent recent activity leave maturity unproven.
65%
Total Score
75
100
88
75
This is the package's first and only release, published 0 days ago, so there is no release history yet to demonstrate sustained maintenance.
No commits or active maintainers were observed in the last 3 months; because the repository is newly published, this is mainly an unproven-maintenance concern rather than evidence of abandonment.
Composer build tooling is present, but no security-scanning tool was detected. For this small type-definition package, the missing scanner is a modest transparency gap.
The repository has no security policy. This is a hygiene gap, though the package's narrow metapackage role limits the significance of the omission.
No GitHub Actions workflows were present, so there were no workflow vulnerabilities to report; this also means no repository automation or security checks were evidenced.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/nesbot-carbon-impl Version ~3.14.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.