The package is clearly scoped, MIT-licensed, and backed by an organization. Consumer documentation is absent, security scanning is not configured, and activity stopped after the initial release burst.
60%
Total Score
75
100
81
83
The package has no README, tests, or changelog. Missing tests and changelog are normal for a published artifact, but missing consumer documentation matters for this library-style package.
Seven releases arrived during the package's first few days, but there has been no release for about three months. That short history and abrupt pause leave maintenance maturity uncertain.
The repository recorded zero commits and zero active maintainers in the last three months. For a package only about three months old, that is a meaningful maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
univeros/container Version ^2.0 | — | — |
univeros/configuration Version ^2.0 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.