This is a small, clearly identified Composer package with an MIT declaration, matching source repository, tests, a complete six-file tree, no install-time scripts, and a minimal dependency profile. However, it was released only hours ago with just two releases, so there is little evidence of operational maturity or sustained maintenance; the repository has no observed commit or issue activity yet, no security scanning or security policy, and no changelog. It is reasonable for experimentation or low-risk use, but production adopters should recognize the limited track record and thin transparency signals.
64%
Total Score
67
100
83
90
The repository is owned by an individual user rather than an organization, so the project has a single-person backing context with no organizational capacity indicated.
The package is brand new, with two releases over only several hours and no meaningful historical window for judging maintenance or release reliability.
No commits or active maintainers were observed in the last three months, but the repository was created and pushed only hours ago, so the signal mainly reflects insufficient history rather than demonstrated abandonment.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity alone is not decisive for a newly published small package.
Composer build tooling is present, but no security scanning tools are configured, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.