It has a matching repository, Apache-2.0 licensing, and packaged tests. The project has no security policy or scanning, and its maintenance record is still unproven.
58%
Total Score
75
100
83
88
This is the package's first and only release, published 0 days ago, so there is no release track record to establish maturity or maintenance reliability.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the project is newly published, this is unproven maintenance rather than evidence of long-term abandonment.
The repository has 0 stars, forks, and watchers. This provides no supporting evidence of community adoption, although popularity is only secondary evidence for a package this new.
Composer is used as the build tool, which is appropriate for this package, but no security scanning tools were detected. The missing scanning is a modest transparency gap.
The repository has no security policy. That weakens disclosure transparency, though it is a hygiene gap rather than a direct dependency-safety verdict.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
react/promise Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.