The package has a useful README, version-specific release notes, and a repository that clearly matches its organization-backed project. Its seven runtime dependencies and lack of security tooling add maintenance overhead for adopters.
55%
Total Score
67
79
75
The package has 16 releases since April 2016, but none in the last 12 months and the latest release was about 4 years ago. This is strong evidence of stale maintenance, although the long history provides some maturity.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's roughly 4-year release gap. No provided maintenance signal compensates for this inactivity.
There were no new or closed issues and no merged pull requests in the last month, with 4 issues still open. This supports the conclusion that current maintenance is limited.
Composer is used for the build, which is appropriate, but no security-scanning tools were detected. This weakens ongoing supply-chain hygiene without making the package unfit by itself.
The repository has no security policy. For a developer CLI that handles project files, this is a transparency and vulnerability-reporting gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^5.2 | — | — |
symfony/filesystem Version ~4.0 | — | — |
symfony/twig-bridge Version ~4.0 | — | — |
cscart/upgrade-builder Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.