The stable major version and focused two-dependency CLI are positives. Organization backing helps, but missing licensing and more than two years since the latest release make long-term adoption uncertain.
58%
Total Score
83
100
81
50
No license declaration, recognized license, or license file was found in the package or repository, leaving the legal terms for reuse unclear.
The package has 14 releases since 2019, but its latest release was more than two years ago and there were no releases in the last 12 months, indicating stalled release maintenance.
There were zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance despite the repository not being archived.
The repository uses Composer and Box for builds, showing a defined packaging process, but it has no security scanning tooling, leaving a modest transparency gap.
The repository has no security policy, reducing clarity about vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version >=4 | — | — |
consolidation/robo Version >=3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.