The package includes tests, a focused source tree, a clear MIT declaration, and no install-time scripts. Its single-release history and zero commits in the last three months leave maintenance maturity unproven; the missing security scanning and policy add smaller concerns.
60%
Total Score
50
100
81
88
One registry publisher account is listed. With a user-owned repository and no observed commit activity, the narrow publishing and ownership base provides limited resilience if the maintainer becomes unavailable.
The package is tied to the uverify registry namespace and the matching elastodev repository, but the repository owner is a user account rather than an organization, so backing capacity is limited and not independently demonstrated.
This is the package's first release, published less than one day ago, so there is no release track record or demonstrated maintenance cadence yet.
The repository recorded zero commits and zero active maintainers over the last three months. Because the package is brand new, this is not proof of abandonment, but it leaves ongoing maintenance unverified.
Composer is used as the build tool, but no security scanning tools were detected. That is a modest transparency and maintenance gap for a library handling identity-related integrations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.