The Apache-2.0 license, included tests, and organization-owned repository provide useful transparency. No security policy or scanning tools are present, so operational assurance is still limited.
66%
Total Score
75
79
50
This is the package's first release, published today, so it has no release track record or demonstrated cadence yet. Its age makes that absence expected rather than evidence of abandonment.
There are zero commits and zero active maintainers in the last three months, but the repository was created or updated today, making this primarily an unproven-maintenance concern rather than evidence of collapse.
Composer is used as the build tool, which is appropriate, but no security scanning tools are configured. This leaves a modest assurance gap for future changes.
The repository has no security policy. For a small type-definition package this is a hygiene gap, but it reduces transparency if vulnerabilities are reported.
Version 0.1 is an early, non-stable-major release, which suggests the API may still change. It is not marked as a prerelease, so the concern is limited.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.