The repository is organization-owned, matches the package, includes tests, and has clear Apache-2.0 licensing. There is no security scanning or policy yet, and the project has no release track record beyond this initial publication.
68%
Total Score
75
79
75
This is the package's first release, published 0 days ago, so there is no observed release cadence or history to establish reliability. Its very recent age makes the lack of history less concerning than an older inactive package, but maturity remains unproven.
There were 0 commits and 0 active maintainers in the last 3 months, but the repository and release are only 0 days old. This leaves ongoing maintenance capacity unproven rather than demonstrating a sustained collapse.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tools are configured, so automated security practice is not demonstrated.
The repository has no security policy. For a small, newly published type-definition package this is a transparency gap, though it is not severe on its own.
Version 0.1 is not a stable major release, which signals an early-stage API. It is not marked as a prerelease, providing some compensation, but compatibility expectations remain limited.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.