It includes tests, a matching repository, and an Apache-2.0 license. Composer dependencies are small and no install-time scripts are present, but security scanning and a security policy are absent.
58%
Total Score
50
100
75
83
The package was created today and has only one release, so there is no release track record to demonstrate sustained maintenance.
There were no commits or active maintainers during the measured three-month period. Because the package was created today, this is mainly missing history rather than evidence of abandonment, but maintenance capacity remains unproven.
Composer is used as the build tool, but no security scanning tools were detected. That is a hygiene gap for supply-chain transparency, not a severe risk on its own.
The repository has no security policy. For this small type-definition package this is a minor transparency gap, though it leaves no documented vulnerability-reporting process.
Version 0.1 is an early release, which is consistent with the package's new status but provides limited evidence of API maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.