The package is well documented, licensed, and backed by a matching repository with tests and a controlled workflow. Its security policy is absent, so the project has less formal transparency while its maintenance record is still unproven.
67%
Total Score
50
100
81
83
The package and repository are owned by the same individual account. That is consistent ownership, though it does not provide the resilience of organizational backing.
This is the first release, published less than one hour before collection, so there is no release history to demonstrate sustained maintenance. Its very recent publication makes this an evidence gap rather than proof of abandonment.
The repository has no commits or active maintainers in the past three months, so ongoing maintenance is not yet demonstrated. Because the package itself is newly published and the repository was pushed immediately beforehand, this is a maturity concern rather than severe abandonment evidence.
The project uses Composer, but no security scanning tooling was detected. The missing scanning automation is a modest hygiene gap, not evidence that the package is unsafe or unmaintained.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This lowers transparency slightly but does not by itself make the release unfit to use.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.