The repository includes tests, a changelog, release notes, and a clear MIT license. Unpinned workflow actions, broad write permissions in one workflow, and no security policy add avoidable hygiene concerns.
69%
Total Score
67
100
88
75
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
The package is young at about four months old and has only two releases, with roughly 96 days between them. This limits evidence of long-term maintenance, though the history is not stagnant.
All 29 recent commits came from one contributor, leaving no demonstrated contributor redundancy if that maintainer becomes unavailable.
Composer build tooling is present, but no security scanning tool was detected. That is a modest transparency and maintenance gap, not evidence of a defect by itself.
The repository has no security policy, so users are given no documented process for reporting vulnerabilities or understanding security response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
symfony/clock Version ^8.0 | — | — |
psr/http-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.