It includes tests, a matching Apache-2.0 license, and an organization-owned repository. Maintenance history is not yet established, and the repository has no security policy or scanning tool.
62%
Total Score
75
100
81
83
This is the first release, published today, so there is no release cadence or history demonstrating sustained maintenance. Its newness is the main reason to remain cautious rather than treating it as abandoned.
There were no commits or active maintainers in the prior three months, but the repository was created or updated on the release date. This is best read as insufficient history for confidence, not evidence of a collapsed established project.
Composer build tooling is present, but no security-scanning tool was detected. For a small type-definition package this is a hygiene gap, though it is not severe on its own.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package's small scope and organization ownership partly reduce the concern.
Version 0.1 is an early, non-stable-major release, which suggests the API may still change. It is not marked as a prerelease, so this is a moderate maturity concern rather than a severe one.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.