The organization-owned repository and clear package documentation improve confidence for adopters. Its small audience and limited engineering safeguards leave less evidence for long-term resilience.
68%
Total Score
75
89
50
The repository recorded no commits and no active maintainers in the last three months. Recent registry releases provide some compensation, but this still weakens evidence of continuing maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but this provides little independent evidence of broad review or adoption.
Composer is used as a build tool, which supports a conventional package workflow, but no security scanning tools were detected. That is a modest transparency and assurance gap.
The repository has no security policy. This does not show a security defect, but it provides less guidance for reporting and handling vulnerabilities.
No GitHub Actions workflows were present, so there were no workflow findings or unpinned actions to assess. This avoids workflow-specific risk but does not demonstrate automated testing or security checks.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.