The small project has limited visible adoption and security process, while its organization backing and recent release provide some confidence. Pin this version deliberately because releases are infrequent and the repository has no automated security scanning.
66%
Total Score
75
83
67
Only one registry publishing account is listed, which is a narrow publishing base, but the repository is owned by an organization, making this less concerning than a lone unbacked maintainer.
Only two releases have appeared since March 2024, with a median interval of about 2.6 years; the release published today is positive but does not establish a strong cadence.
The repository has 1 star, 0 forks, and 2 watchers, indicating very limited visible adoption; popularity is supporting evidence, so this is a modest concern rather than a verdict.
Composer is used for builds, but no security scanning tools are configured, leaving a meaningful security-process gap.
The repository has no published security policy, reducing transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.