The project is small but actively developed and clearly packaged for its stated scaffolding role. Organizational ownership and a matching repository help offset the limited security process and concentrated contributor base.
68%
Total Score
75
89
67
The package runs a post-create-project-cmd lifecycle script, which is relevant to its stated module-generation role but adds install-time behavior that consumers must account for.
Only one registry account has publish access. This is a limited publishing base, although the repository's organization ownership provides some broader project backing.
One contributor made all 14 commits in the last three months. Organization ownership reduces the risk somewhat, but no second active contributor is shown to provide handoff capacity.
The repository has 0 stars, 1 fork, and 0 watchers. Popularity is limited supporting evidence and does not outweigh the observed release and commit activity, but it provides little external validation.
Composer is used as the build tool, but no security scanning tools were detected. That leaves a meaningful transparency and detection gap for a dependency ecosystem package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.