The MIT license, release notes, and substantial README provide useful transparency for consumers. Recent repository activity is absent, and the linked repository does not identify this package, leaving long-term maintenance and ownership less certain.
64%
Total Score
75
100
81
75
Twelve releases in the last 12 months show active initial publishing, but the very short median interval suggests a young project whose longer-term cadence is not yet established.
The repository recorded zero commits and zero active maintainers over the last three months. That is a meaningful maintenance concern for a young package, although the release was published during this period.
The repository name does not match the package name and its README does not mention the package. The release notes explain a rename to cipi/agent, but the linkage is still less clear than expected.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest verification gap for a package that handles deployments, tokens, and server integration.
The repository has no security policy. This does not prove poor security, but it reduces transparency about how vulnerability reports are handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fakerphp/faker Version ^1.23 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/routing Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.