The MIT license, clear README, focused file tree, and lack of install-time scripts make the package straightforward to evaluate and install. Its short history and single-contributor maintenance leave limited evidence that support will continue. No security policy or scanning tooling is present, adding a modest transparency concern.
62%
Total Score
63
100
81
83
One registry publishing maintainer is consistent with a small user-owned project, but it provides little publishing redundancy by itself.
Only two releases exist, both published on the same day, and the package is 81 days old. That leaves little evidence of an established release process or sustained maintenance.
One contributor made all two commits in the last three months. Because the repository is user-owned rather than organization-owned, there is no shown backing to offset this concentration.
Only two commits were recorded in the last three months, all within a project that is 81 days old. This is limited maintenance evidence rather than proof of abandonment.
Composer is used for the build, but no security scanning tooling is present. For a small package this is a modest transparency and maintenance-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.2 || ^7.0 || ^8.0 | — | — |
illuminate/console Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.