Package Health

atoms/cli

atoms/cli 0.6.0 appears usable and reasonably well maintained, with a clear MIT license, substantial source and test coverage, active recent development, an unarchived organization-owned repository, and no install-time lifecycle scripts. The main limitations are that the package is very young at 22 days old, remains on a 0.x version, has only two active contributors, lacks a security policy and security-scanning tooling, and has no meaningful public popularity or issue/PR activity yet. These concerns warrant monitoring rather than making the package unfit to depend on.

Latest 0.6.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package has nine runtime dependencies, including platform extensions and several substantial libraries. This is plausible for a CLI that builds, validates, and deploys applications, but it increases the dependency surface that must be maintained.

Release historycaution

Eight releases in 22 days, with a median interval of about 1.5 days, shows active delivery but also leaves little long-term maintenance history to evaluate.

Repo issue activitycaution

There were no new or closed issues and no pull-request activity in the measured month. This provides little evidence of community engagement, although the package is very young and the repository directs development to a monorepo.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, and the package's very recent 22-day history makes these low counters a limited concern rather than a decisive negative.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a transparency and maintenance gap, not evidence that the package is unsafe by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
atoms/core
Version ^0.6
—
—
symfony/console
Version ^6.4 || ^7.0
—
—
symfony/process
Version ^6.4 || ^7.0
—
—
colinodell/json5
Version ^2.3 || ^3.0
—
—
nikic/php-parser
Version ^5.0
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform