Usable with caveats: it is a very new project with only seven days of history and no tests, changelog, or security policy. Organization backing, recent commits from two contributors, a clear repository match, and no install-time scripts provide useful safeguards.
68%
Total Score
90
100
81
90
A 1,605-character README documents the command and supported project types, but neither the artifact nor repository contains tests or a changelog. For a project-scaffolding CLI, the missing tests reduce confidence in template-generation behavior and the missing changelog reduces release transparency.
The package is only 7 days old, despite having 4 releases in that period; this shows active initial work but provides little evidence of long-term maintenance or release stability.
The repository has 2 commits in the last 3 months from 2 active maintainers; both contributors are active, but the very low total reflects the project's short history rather than established maintenance.
Composer is used as a build tool, but no security-scanning tool is configured. The missing scanner is a transparency gap for supply-chain hygiene, though it is not by itself evidence that the release is unsafe.
The repository has no security policy. For a small, newly published CLI this is a genuine disclosure and maintenance gap, although the absence of install-time scripts limits the operational exposure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.