The source matches the package, includes a README, and uses Composer without install hooks. The MIT declaration and recent activity are reassuring, though broader security transparency is limited.
68%
Total Score
50
88
75
Only one registry account can publish releases. This is manageable for a user-owned project but leaves release continuity dependent on a single person.
The repository is owned by an individual account rather than an organization, so the concentrated maintainer and contributor activity is not offset by visible organizational backing.
One contributor made 100% of the recent commits, creating a meaningful continuity risk despite the project's recent activity.
Fifteen commits were made in the last 3 months, demonstrating ongoing development, although all activity came from one maintainer.
Composer is used for builds, but no security-scanning tooling was detected. That limits automated visibility into dependency and code risks.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.