The MIT declaration and recent commit activity provide useful transparency. The source has no tests or security policy, and all 21 recent commits come from one contributor. Pin version 1.0.44 rather than tracking frequent updates.
62%
Total Score
63
100
86
83
One registry maintainer is consistent with the single-user project backing shown for this package. It reinforces the concentration concern but does not independently indicate abandonment.
The repository is owned by a personal GitHub account rather than an organization, so there is no provided evidence of organizational handoff capacity to offset the concentrated contributor base.
The package is only 8 days old but already has 42 releases, with a median interval of about 19 minutes. That unusually rapid history provides little evidence of a settled release process.
All 21 commits in the last 3 months came from one contributor, leaving the project dependent on a single active maintainer and increasing continuity risk.
Composer is used as a build tool, but no security-scanning tool was detected. For a young library this is a modest transparency and assurance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
websyspro/utils Version ^1.0 | — | — |
websyspro/package Version ^1.0 | — | — |
websyspro/connection Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.