The package includes tests, a matching organizational repository, and clear Apache-2.0 licensing. Its maintenance record is too new to establish reliability, and the repository has no security policy or scanning tools.
62%
Total Score
75
100
81
83
This is the package's first release, published 0 days ago, with only one release and no established release cadence. That limits evidence of maintenance maturity, though it may simply reflect a newly created package.
There were 0 commits and 0 active maintainers in the previous 3 months, but the package is only 0 days old. This is insufficient history rather than evidence of a collapsed established project.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tool is configured. The missing scanning is a modest hygiene gap for this small, low-complexity package.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package is a small type-definition artifact rather than a large runtime component.
Version 0.1 is not a stable major release, so the API may change before maturity is established. It is not marked as a prerelease, which provides some compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.