It has tests, a matching repository, an Apache-2.0 license, and no install scripts. Organization backing helps, but the project has too little history to establish mature maintenance.
72%
Total Score
75
100
79
83
The package was first released 0 days ago and has only one release, so there is no release track record yet. This is a meaningful maturity gap, though its very recent launch limits abandonment conclusions.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Because the package is 0 days old, this is better read as insufficient maintenance history than evidence of a long-standing collapse.
Composer is used as the build tool, which fits the package, but no security-scanning tooling was detected. For this small package that is a modest transparency gap rather than a severe risk.
The repository has no security policy. This limits the documented process for reporting vulnerabilities, although the package's narrow type-definition scope reduces the practical impact.
Version 0.1 is not a stable major release, indicating an early-stage API. It is not marked as a prerelease, so the concern is limited to maturity rather than an explicit unstable-release warning.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.