The package is very new, with minimal documentation and no demonstrated maintenance beyond its initial publication. Its MIT declaration, lack of install scripts, and unarchived repository are reassuring, but the source repository has no tests, security policy, or README package reference.
55%
Total Score
50
71
67
Both the package and linked repository contain only README.md and composer.json, leaving little evidence of implementation maturity or consumer-facing documentation.
The artifact includes a README, but it is only 18 characters long and provides no practical integration guidance; the absence of tests and a changelog is normal for a published package artifact.
This is the first release, published on the same day as the assessment, so there is no release cadence or track record yet. Its freshness limits confidence but does not by itself show abandonment.
The repository has zero commits and zero active maintainers in the last three months, although it was created or pushed on the same day as this first release. That provides no demonstrated maintenance history yet.
The repository name matches the package, but its README does not mention the package, leaving the package-to-source relationship less clearly documented. The matching name is a compensating signal, so this remains a modest caution.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.