The package has a substantial README, repository tests, an MIT license, and no install-time scripts. A security policy and security-scanning tools are absent, so ongoing trust and maintenance still depend heavily on the backed organization.
68%
Total Score
83
100
79
75
This package is 33 days old and has only one release, so there is little release history from which to judge stability or sustained maintenance.
All 59 recent commits came from one contributor, creating a concentrated maintenance dependency; the organization-owned project provides some backing but no second active contributor is shown.
Composer is used as the build tool, but no security-scanning tools are reported, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users are given no documented channel or process for reporting vulnerabilities.
The current v0.1.0 release is not on a stable major version, which is normal for a new package but indicates that compatibility may still change.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.