Usable with caveats: the package is clearly identified, licensed, documented, and backed by an active organization, but its registry release history is stale and recent repository work is limited to one contributor and one commit.
65%
Total Score
67
88
75
The package has had no registry release in the last two years, despite three releases shortly after its September 2024 launch. This raises maintenance and currency concerns, although the repository was pushed more recently.
All recent repository activity came from one contributor, creating concentration risk. Organization ownership provides some ability to hand maintenance off, but no second active contributor is shown.
Only one commit was recorded in the last three months. That shows some recent activity but is too little evidence of a sustained maintenance cadence.
The repository uses Composer, but no security-scanning tooling is detected. For this small CLI, the missing scanning setup is a transparency gap rather than a severe standalone risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This matters for transparency, though the package's small CLI scope limits the severity of the gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.