Usable with caveats: it is actively released, licensed, tested, and backed by an organization, but the linked repository shows no commits or active maintainers in the last three months. The package is also an early 0.x release with little adoption and no security policy.
62%
Total Score
63
100
83
88
Two registry maintainer entries are listed, though the names appear to be duplicate spellings of one person. Because the repository is organization-owned, a short registry maintainer list is not by itself a serious concern.
The repository recorded 0 commits and 0 active maintainers in the last three months, despite frequent registry releases. The mismatch leaves current source maintenance unclear and is the main reason for caution.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently negative for a small stable project, but it provides little evidence of an engaged user or contributor community.
The repository has only 2 stars, 3 forks, and 2 watchers, indicating limited external adoption. Popularity is supporting evidence, so this lowers confidence in maturity but does not make the package unsafe to adopt alone.
Composer build tooling is present, but no security scanning tools were detected. The build setup supports reproducibility, while the missing scanning is a modest transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.