The MIT license, tests, README, and matching organization repository provide a solid foundation. The install-time script and absent security policy add modest operational concerns, while the project has little recent activity.
58%
Total Score
75
90
50
The package uses a post-create-project-cmd lifecycle script. This is an operational consideration because installation can execute package-defined behavior, but the signal does not show that the script is unsafe.
The package has 15 releases since July 2019, but its latest release was about five and a half years ago and it has had no releases in the last 12 months. This materially raises abandonment risk despite the earlier release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. That indicates no current maintenance capacity.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the presence of tests, a license, and an organization-backed repository partly offsets the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.0 | — | — |
composer/semver Version ^3.0 | — | — |
scssphp/scssphp Version ^1.0 | — | — |
laminas/laminas-text Version ^2.7 | — | — |
matthiasmullie/minify Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.