The package is well documented, licensed, tested in the repository, and uses Composer security scanning. Its young release history, missing security policy, concentrated contribution, and unpinned workflow actions leave meaningful maturity and build-reproducibility concerns.
62%
Total Score
75
100
88
67
Only one registry account has publishing access, which is a modest publishing-capacity concern; the organization-owned repository provides some backing but does not remove the concentration entirely.
The package is only 46 days old and all 13 releases occurred within three days, showing active initial development but limited evidence of long-term maintenance.
One contributor made all 18 commits in the last three months. Organization ownership offers some handoff potential, but no second active contributor is shown, leaving a real continuity risk.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented for a package that manages local infrastructure.
Version v0.7.1 is not a stable major release, so its API and behavior may still change materially for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.0 || ^8.0 | — | — |
cboxdk/platform Version ^0.11.0 | — | — |
illuminate/http Version ^12.0 || ^13.0 | — | — |
symfony/process Version ^7.0 || ^8.0 | — | — |
illuminate/console Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.