The package includes a clear license, a substantial README, repository tests, and automated security tooling. Its individual ownership and absent security policy provide less assurance about long-term support and incident handling.
62%
Total Score
50
86
83
The package and repository are owned by an individual account rather than an organization, so there is less visible institutional backing for continuity, though this is not evidence of abandonment by itself.
Only two releases appeared within minutes, and the package is effectively one day old, so there is not enough history to establish a dependable maintenance pattern.
No commits or active maintainers were observed in the last three months, but the repository is only about one day old, so this is primarily an unproven maintenance record rather than evidence of collapse.
No security policy was found, leaving incident-reporting and vulnerability-response expectations undocumented for a package that makes network API calls.
Version 0.1.1 is not a stable major release, which signals an early API and maturity stage despite not being marked as a prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
symfony/clock Version ^7.4 || ^8.0 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
symfony/http-client Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.