Usable with caveats: this is a newly published package with only one release, so its maintenance record is unproven. The linked repository is active and mentions the package, but has no recent commits, tests, or security scanning yet.
62%
Total Score
67
100
83
75
The package is backed by an individual repository owner rather than an organization, so the project has a narrower visible ownership base and potentially higher continuity risk.
The package was published today and has only one release, so there is no meaningful history demonstrating sustained maintenance or release reliability.
There were no commits and no active maintainers in the last three months, but the repository and package are newly created, so this is weak evidence of abandonment rather than a severe risk.
The repository has no stars, forks, or watchers. For a package released today this mainly reflects lack of exposure, but it provides no independent maturity evidence.
Composer build tooling is present, but no security scanning tools are configured; this is a modest transparency and maintenance gap for a new package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.