Healthy and reasonable to depend on, with a clear package structure, tests, active recent development, and organization backing. The main caveats are the very young project history and limited security-process evidence.
82%
Total Score
83
100
88
80
The project is only 61 days old with four releases, so its long-term maintenance record is not yet established. Releases have arrived about every 3 days, which is a positive sign of early activity.
Two contributors provide some continuity, although the leading contributor made 75% of the recent commits, leaving maintenance somewhat concentrated. Organization backing partly compensates for this concentration.
Composer is used as a build tool, but no security-scanning tool was detected, leaving automated vulnerability checking unproven.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
The CI workflow does not declare top-level token permissions. No write permissions were observed, but the missing explicit restriction provides weaker workflow hardening evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.