The MIT license, small dependency surface, and organization ownership provide useful transparency. The package is clearly identified and actively released, but its security and contributor safeguards remain limited.
68%
Total Score
67
100
94
50
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown to reduce current concentration.
Only one commit was recorded in the last three months, so recent development activity is thin despite the recent release cadence.
Composer is used for builds, but no security scanning tool is reported, leaving a modest gap in ongoing project safeguards.
The repository has no security policy, which reduces transparency about vulnerability reporting and maintainer response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/clock Version >=6.2 | — | — |
psr/simple-cache Version ^1.0|^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.