The artifact includes tests, matching Apache-2.0 licensing, and no install-time scripts. Its release history is less than one day old and it has no commits in the past three months, so maintenance maturity remains unproven.
55%
Total Score
75
100
89
83
This package has only one release and is less than one day old, so there is no demonstrated release continuity yet. Its very recent publication partly explains the gap but does not establish maintenance maturity.
There were no commits and no active maintainers during the past three months. Because the repository was created less than one day ago, this is partly an age effect, but maintenance capacity is still unproven.
The repository uses Composer, providing build tooling, but no security-scanning tool was detected. The missing scanner is a modest transparency gap, not a severe risk on its own.
The repository has no security policy. This reduces disclosure transparency, although the package's very recent creation makes the absence less informative than it would be for a mature project.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version 2.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.