The package includes tests, a matching organization-owned repository, and clear Apache-2.0 licensing. Its evidence base is still too new to establish dependable ongoing maintenance, so pin this release and reassess future activity.
58%
Total Score
75
100
81
83
This is the first release, published today, with only one release and no established release cadence. That makes maintenance maturity unproven rather than demonstrating abandonment.
The repository has recorded zero commits and zero active maintainers in the last 3 months, which is expected for a repository created today but provides no evidence of sustained maintenance.
The repository uses Composer build tooling, but no security scanning tools were detected. For this small definition package, the missing scanning is a minor transparency gap rather than a severe risk.
No security policy was found. This is a modest transparency gap for a package with little observed history, though the package's narrow type-definition scope limits the practical impact.
Version 0.1 is an early, non-stable major version, so APIs may change as the package matures. The absence of prerelease labeling does not compensate for its early lifecycle.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.