This is a very new, pre-1.0 package with only four releases published within the same day, so its long-term maintenance and stability are not yet demonstrated. However, it is backed by a matching organization-owned repository, has repository tests and CI workflows, uses read-only workflow permissions, has no dangerous workflow patterns or install-time lifecycle scripts, is not deprecated or archived, and is clearly licensed under MIT. The absence of repository commit activity and issue activity is not yet strong abandonment evidence because the package is only hours old, but the lack of a security policy and security scanning, along with limited adoption signals and no packaged README, warrants caution before making it a critical dependency.
68%
Total Score
75
100
72
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pestphp/pest Version ^4.0 | — | — |
pestphp/pest-plugin Version ^4.0 | — | — |
pestphp/pest-plugin-arch Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.