This release presents a generally healthy but very immature dependency profile. The repository is active, unarchived, correctly associated with the package, well documented, tested, and supported by changelog and release practices; its workflow also uses read-only permissions and avoids detected dangerous patterns. However, the package is only 3 days old, has only four releases, and all 103 recent commits come from one maintainer, creating meaningful continuity and bus-factor risk. The absence of repository security-scanning tools is an additional hygiene gap, though the presence of SECURITY.md and strong project scaffolding partly compensates. It is reasonable to evaluate or adopt with normal review, but its maintenance track record is not yet established.
78%
Total Score
75
100
75
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yosymfony/toml Version ^1.0 | — | — |
laravel/prompts Version ^0.3.24 | — | — |
symfony/console Version ^7.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
ircmaxell/php-cfg Version ^0.8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.