Its Apache-2.0 licensing, direct implementation dependency, and matching organization repository make the package structure clear. There is not yet enough history to judge long-term maintenance, so pin this exact version.
60%
Total Score
75
100
80
75
The package was first and last released 0 days ago, with only 1 release. That makes its maintenance record and release reliability unproven, despite the package being newly published rather than abandoned.
The repository has 0 commits and 0 active maintainers in the last 3 months, but it was created 0 days ago, so this reflects missing history more than a demonstrated collapse in maintenance.
Composer is used as the build tool, which fits this small Packagist metapackage, but no security scanning tools were detected. That is a modest transparency gap rather than a severe risk.
The linked repository has no security policy. This is a minor transparency gap for a newly published, minimal package, though the package does not expose install-time lifecycle scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/orchestra-testbench-impl Version ~11.2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.