atoms/cli 0.6.0 appears usable and reasonably well maintained, with a clear MIT license, substantial source and test coverage, active recent development, an unarchived organization-owned repository, and no install-time lifecycle scripts. The main limitations are that the package is very young at 22 days old, remains on a 0.x version, has only two active contributors, lacks a security policy and security-scanning tooling, and has no meaningful public popularity or issue/PR activity yet. These concerns warrant monitoring rather than making the package unfit to depend on.
78%
Total Score
88
50
75
90
The package has nine runtime dependencies, including platform extensions and several substantial libraries. This is plausible for a CLI that builds, validates, and deploys applications, but it increases the dependency surface that must be maintained.
Eight releases in 22 days, with a median interval of about 1.5 days, shows active delivery but also leaves little long-term maintenance history to evaluate.
There were no new or closed issues and no pull-request activity in the measured month. This provides little evidence of community engagement, although the package is very young and the repository directs development to a monorepo.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, and the package's very recent 22-day history makes these low counters a limited concern rather than a decisive negative.
Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a transparency and maintenance gap, not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
atoms/core Version ^0.6 | — | — |
symfony/console Version ^6.4 || ^7.0 | — | — |
symfony/process Version ^6.4 || ^7.0 | — | — |
colinodell/json5 Version ^2.3 || ^3.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.