It has a clear Apache-2.0 license, tests, and no install-time scripts. The organization-backed project is coherent, but its maintenance record is too short to establish reliability.
60%
Total Score
75
100
81
83
The artifact includes tests, which is a small positive. It has no README, a minor consumer-documentation gap for an implementation package.
This is the package's first release, published today, so there is no release track record yet; the linked repository is present but provides no longer-term evidence.
There were zero commits and zero active maintainers in the last three months. Because the repository was only created today, this is mainly an unproven maintenance record rather than evidence of abandonment.
Composer is used for the build, but no security-scanning tool was detected. That is a modest hygiene gap, not a severe supply-chain concern by itself.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for future consumers.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/link Version 2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.