Tests, a matching Apache-2.0 license, and organization backing provide useful basics. Its single release and lack of established commit history leave maintenance maturity unproven, while missing documentation and a security policy add smaller concerns.
68%
Total Score
75
100
71
88
Tests are present in the artifact and repository, which is positive. The package has no README, reducing consumer guidance, while the absent changelog is normal packaging practice and not a gap by itself.
This package has only one release and is brand new, so there is no release track record from which to judge maintenance or stability.
There were no commits or active maintainers in the previous three months. Because the repository is newly created, this primarily means ongoing maintenance capacity is not yet demonstrated rather than proving abandonment.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap, not a severe risk on its own.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified. For a small, newly published type-definition package this is a minor concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.