The README clearly explains the generated type-package role, and its single dependency is explicit. Organization ownership, matching repository metadata, and a valid Apache-2.0 license support adoption, but the project has no security scanning.
70%
Total Score
75
100
88
83
This package is newly published, with one release and no established release interval, so its maintenance record is unproven. Its narrowly scoped, version-specific metapackage purpose partly explains the limited history.
The repository has zero commits and zero active maintainers in the last three months. Because the package was released only recently, this mainly shows that ongoing maintenance capacity is not yet demonstrated rather than proving abandonment.
The repository uses Composer, which fits the package ecosystem, but no security-scanning tools were detected. For a tiny metapackage this is a modest transparency and assurance gap.
The linked repository has no security policy. This is a minor transparency gap for a package with a very small artifact, but it leaves no documented vulnerability-reporting path.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/slevomat-coding-standard-impl Version ~8.31.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.