The package is small and focused, with a clear README, tests, MIT licensing, and no install-time scripts. Its source project is new and has little operating history, so future maintenance depends heavily on one person; no security policy or scanning is visible.
68%
Total Score
50
100
88
75
The package is only 97 days old and has two releases, spaced about 19 days apart. This shows recent publishing activity but provides limited evidence of long-term maintenance.
One contributor made 100% of the recent commits, leaving no demonstrated maintainer redundancy. The repository is user-owned rather than organization-owned, so there is no provided backing evidence to offset this concentration.
The repository recorded one commit in the last three months, indicating very limited observed development activity. The package is new, which partly explains the small history but does not remove the maintenance uncertainty.
Composer is used for builds, but no security scanning tool was detected. This is a modest transparency and maintenance gap, not evidence that the release is unsafe.
The repository has no security policy. For a small validation package this is a limited process gap, but it reduces transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
validators/sa Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.