The package includes tests, an Apache-2.0 license, and organization-backed source with no install scripts. Security scanning is absent, and the project is too new to demonstrate sustained maintenance.
70%
Total Score
75
100
79
88
This is the package's first release, published 0 days ago, so there is no release track record yet; its very recent age makes the gap understandable but limits maturity evidence.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the package is newly published, this is not evidence of a collapsed project, but it leaves sustained maintenance unproven.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are reported. The missing scanning is a modest transparency and hygiene gap.
The repository has no security policy. For a small type-definition package this is a limited gap, but it provides no documented channel or process for handling security reports.
Version 0.1 is not a stable major release, which signals an early-stage API; it is not marked as a prerelease, so this is a moderate maturity concern rather than a severe warning.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.