Clear documentation, tests, and release notes make integration easier. The MIT license, security policy, and tightly scoped pinned CI provide useful transparency despite the project's limited history.
63%
Total Score
50
88
100
The package and repository are owned by the same individual account, so the one-person maintenance concentration is not offset by organization backing.
The package is only 1 day old with three releases, spaced about 22 hours apart, so maintenance and compatibility over time are not yet demonstrated.
All recorded recent commits came from one contributor, leaving no demonstrated contributor redundancy for this user-owned project.
Only one commit was recorded in the last three months, with one active maintainer. The recent release activity helps explain the timing, but sustained maintenance is not yet established.
Composer build tooling is present and a security policy exists, but no security-scanning tool was detected; this is a modest transparency gap for a package handling untrusted archives.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.