It includes tests, a matching organization-owned repository, and a clear Apache-2.0 license. Treat it as an unproven dependency until its maintenance history develops.
62%
Total Score
75
100
71
88
The artifact includes tests, and the repository also has tests; the missing changelog is normal for a newly published package, while the absent README is a minor documentation gap for a type-definition package.
This is the package's first release, published today, with only one release and no established release cadence. The absence of history limits evidence of maintenance maturity but does not indicate abandonment by itself.
There were no commits and no active maintainers in the last three months, although the repository was created or updated today. This provides little evidence of ongoing maintenance beyond initial publication.
Composer is used as a build tool, which fits the package, but no security-scanning tooling is configured. That is a hygiene gap rather than a severe dependency risk.
The repository has no security policy. For a small type-definition package this is a transparency gap, but it is not evidence of unsafe code on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.