There are no automated security checks or security policy, and the project contains only one source file with no tests. Clear licensing, a matching repository, and a usable README provide useful transparency for this small package.
58%
Total Score
50
79
67
The artifact and repository each contain five files, including one source file, a manifest, README, and license. This minimal structure is consistent with a narrowly scoped command package, though it provides little evidence of broader maintenance maturity.
The package is backed by an individual repository owner rather than an organization. That is not inherently unhealthy, but it provides less visible continuity than established organizational backing when combined with the limited activity.
The package has only two releases, both in September 2020, with no releases in the last 12 months. That long period without a new release is a meaningful maintenance concern for a dependency.
Composer is used as the build tool, but no security scanning tooling is present. For a small package this is a hygiene gap, not evidence that the release is unsafe by itself.
The repository is not archived, but its last recorded push was in May 2021, leaving several years without observed source updates. The repository remains available, which avoids the more severe abandonment signal of archival.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.