The package is clearly documented and backed by an organization, with a license and no install-time scripts. Its history is too short to establish maintenance, and the workflows include broad app-token permissions plus a release note requiring a patch.
55%
Total Score
75
100
79
75
The package has a 3,014-character README and an exact-version GitHub release with release notes. Missing tests and a changelog are normal for a published PHP artifact, but the notes warn that a required patch must be installed.
This is the first recorded release, published less than one day ago, so there is no release track record or demonstrated cadence to support maintenance confidence.
No commits or active maintainers were recorded in the last three months. Because the package itself was released less than one day ago, this may reflect a new project, but it leaves maintenance capacity unproven.
The repository has no security policy. This is a transparency gap for a package that manages authentication tokens, although it does not by itself show abandonment.
Version 0.0.1 is an early, non-stable-major release, which increases compatibility and maturity uncertainty despite not being marked as a prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
neos/neos Version ^8.3 | — | — |
flownative/token-authentication Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.