Frequent releases and a stable major version support active publishing. The broad 19-package runtime dependency set and missing security controls increase maintenance and review overhead.
62%
Total Score
50
50
89
50
The package declares 19 runtime dependencies, including database, messaging, email, HTTP, authentication, and monitoring components. That broad dependency surface increases update and transitive-supply-chain overhead.
The package defines a post-create-project-cmd script. This can perform actions during project creation and merits review, but the signal alone does not show harmful or unnecessary behavior.
The repository is owned by an individual user rather than an organization. Combined with zero active maintainers in the last three months, this indicates limited visible maintainer capacity.
The repository recorded 0 commits and 0 active maintainers during the last three months. This is a meaningful maintenance warning, though the recent release history shows publishing activity that partly offsets it.
The repository has 0 stars, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these low numbers provide little external validation or community resilience.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sentry/sdk Version ^4.0 | — | — |
twilio/sdk Version ^6.43 | — | — |
ramsey/uuid Version ^4.7 | — | — |
predis/predis Version ^2.1 | — | — |
symfony/cache Version ^6.0.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.