Tests and an Apache-2.0 license make the artifact easy to inspect. Its organization-backed repository is not archived, but there is not enough history yet to establish dependable maintenance.
68%
Total Score
75
100
79
88
The package is 0 days old with one release and no established release cadence, limiting evidence of maturity; this is expected for a newly published package rather than evidence of abandonment.
There were no commits or active maintainers in the last three months. Because the repository was created at the time of this first release, this weakens maturity evidence but does not by itself establish abandonment.
Composer is used as the build tool, which fits the package, but no security-scanning tool was detected; for this small definitions package that is a modest hygiene gap rather than a severe risk.
The repository has no security policy. That reduces reporting transparency, although the package is a small type-definition artifact with no indication of sensitive runtime behavior.
Version 0.1 is an early, non-stable-major release, so API changes are more likely; it is not marked as a prerelease, which provides some compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.