Healthy and usable, with some maintenance and workflow caveats. The project has strong packaging, tests, release documentation, and active pull-request throughput, but has published no release in over a year and shows no commits in the last three months.
78%
Total Score
63
100
94
70
One workflow uses pull_request_target for Dependabot auto-merge, creating some elevated workflow risk, but no untrusted checkouts or script-injection patterns were detected across the 12 analyzed workflows.
The package uses post-autoload-dump, post-install, and post-update scripts. These add installation-time behavior and warrant review for a CLI package, but the signal alone does not show that they are unsafe or excessive.
Only one registry account has publish access. This is consistent with the matching individual repository owner, but it leaves limited publishing redundancy if that maintainer becomes unavailable.
The registry namespace and repository owner match, providing consistent ownership evidence. The owner is an individual rather than an organization, so the single-owner structure limits redundancy but is not itself a severe risk.
The project has 102 releases over roughly 3 years, but it has made no registry release in the last 12 months despite previously releasing frequently. This is a meaningful maintenance concern for a dependency on the latest release.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.