61%
Total Score
caution
A first release with no activity history provides little evidence of long-term maintenance.
This is the package's first release, published less than a day ago, so there is no release cadence or maintenance history to assess. That is a meaningful maturity gap for a dependency, though it may simply reflect the package being newly introduced.
There were zero commits and zero active maintainers in the preceding three months, although the repository was only just created or published. This leaves maintenance capacity unproven rather than demonstrating established abandonment.
The repository has zero stars, forks, and watchers, so there is no community adoption evidence supporting maturity. For a package published less than a day ago, this is weak negative evidence rather than proof of poor quality.
Composer build tooling is present, which fits the package ecosystem. No security scanning tool was detected, leaving a modest transparency and hygiene gap.
The repository has no security policy. This does not make the package unsafe by itself, but it provides no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.