This is a well-scaffolded but extremely new package: it has only one release and is still at v0.1.1, so maintenance maturity and long-term stability cannot yet be established. The linked repository is organization-owned, active enough to have been pushed recently, matches the package, includes tests, a changelog, CI and publishing workflows, and is not archived. Dependency and install behavior are comparatively controlled, but the repository has no security policy or security scanning, and one workflow grants top-level write permissions. It is reasonable to evaluate for limited use, but adoption should account for the lack of release history and operational track record.
68%
Total Score
83
100
78
80
The package is only 0 days old with one release and no established release cadence, leaving maintenance continuity and maturity unproven.
There are no issues or pull requests and no activity in the last month; for a repository created alongside a release today this is inconclusive, but it does not demonstrate an established maintenance process.
The repository has zero stars, forks, and watchers. Because the package is newly released, this is weak supporting evidence rather than a standalone abandonment verdict, but it provides no external maturity signal.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-process gap that is relevant to dependency consumers.
No repository security policy is present, reducing transparency about vulnerability reporting and coordinated response expectations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.