Clear licensing, a focused dependency, and a matching organization-owned repository provide useful transparency. The package is narrowly scoped, but its maintenance and security track record are not yet established.
65%
Total Score
75
100
88
83
The package is brand new: it has one release and is 0 days old, so there is no release history from which to judge sustained maintenance.
There were zero commits and zero active maintainers in the last three months. Because the repository is only 0 days old, this mainly shows that ongoing maintenance has not yet been demonstrated.
Composer is used as the build tool, but no security-scanning tool was detected. This is a minor hygiene gap for a tiny package, not a severe risk by itself.
The repository has no security policy. For a small type-definition metapackage this is a modest transparency gap, though the package does not present a broad runtime surface.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/psy-psysh-impl Version ~0.12.24.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.