The package is clearly documented, licensed, tested, and tightly scoped with no install-time scripts. Its very recent history and lack of recorded maintenance activity leave long-term support unproven; the repository also lacks a security policy and automated security scanning.
68%
Total Score
75
100
79
75
The package is only 1 day old with four releases, so its release history shows active initial publishing but no evidence of sustained maintenance yet.
No commits or active maintainers were recorded in the last 3 months. Because the repository is only 1 day old, this mainly shows that ongoing maintenance is not yet established rather than proving abandonment.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful maintenance and transparency gap.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
Version v0.1.3 is not a stable major release, which signals an early API and project maturity stage despite not being marked prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.