It includes tests, a README, and a clear license. The small popularity footprint and absent security scanning add limited confidence for a tool handling GitHub tokens.
78%
Total Score
75
50
89
75
Twelve runtime dependencies, including GitHub API and framework components, create meaningful maintenance surface but are reasonable for this command-line application.
The package and repository are owned by the same individual account, confirming ownership alignment but offering no organizational handoff capacity.
All recent commits came from one contributor, so maintenance depends heavily on a single person despite the recent activity.
The repository has one star and two forks; this is limited supporting evidence, but popularity alone does not outweigh active maintenance.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mezzio/mezzio Version ^3.26.0 | — | — |
composer/semver Version ^3.4.4 | — | — |
symfony/console Version ^6.0 || ^7.4.1 | — | — |
guzzlehttp/guzzle Version ^7.10.0 | — | — |
knplabs/github-api Version ^3.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.