Risky to adopt: the package has had no new release or repository activity since March 2017, with no active maintainers visible in recent activity. It is licensed, matches its source repository, and has a small, clear CLI artifact, but its long abandonment makes ongoing compatibility and support unlikely.
42%
Total Score
25
70
75
This is a single-release package first and last released on March 20, 2017, with no releases in the last 12 months. The long period without a release is a substantial abandonment concern for a dependency.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the package having been inactive for years. No provided signal compensates for this lack of observed maintenance.
There is one open issue and no issue or pull-request activity in the last month. This adds to the maintenance concern, although the small package scope means limited issue volume is not independently severe.
The repository has zero stars and forks and only one watcher, providing little evidence of a user or contributor community that could help sustain it. Popularity is supporting evidence rather than decisive on its own, so this is a caution rather than a danger.
The repository has no security policy. For a command-line tool that handles Packagist authentication, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^3.2 | — | — |
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.