It includes tests, a matching repository, Apache-2.0 licensing, and no install-time scripts. The organization-backed project has sensible PHP/session dependencies, but there is not yet enough history to establish long-term maintenance.
67%
Total Score
75
100
75
83
This is the package's first and only release, published today, so there is no release history to demonstrate sustained maintenance. Its very recent publication limits how strongly the lack of history should be penalized.
The repository has recorded zero commits and zero active maintainers in the last three months, but it was also created or pushed today. This leaves maintenance capacity unproven rather than showing an established project has gone dormant.
Composer is used as a build tool, showing basic project tooling. No security scanning is configured, which is a modest hygiene gap for a new package but not a severe health risk on its own.
The repository has no security policy. For a small type-definition package this is a limited transparency gap, but it leaves vulnerability-reporting expectations unspecified.
Version 0.1 is an early, non-stable-major release, which signals an immature API and a higher likelihood of breaking changes. It is not marked as a prerelease, providing a small counterpoint.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.