Usable with caveats: it is a small, clearly identified MIT-licensed generator with a readable README and no deprecation or archive status. However, development stopped about nine months ago after a burst of releases, with no recent commits, no tests, and only one maintainer.
60%
Total Score
75
100
83
88
One registry publisher is consistent with a personal project, but it also indicates a thin publishing base and limited redundancy if the maintainer becomes unavailable.
The package has nine releases, but all were published within roughly four days and the latest release was about nine months ago. That pattern suggests an initial burst without evidence of continuing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old last push, this is a meaningful abandonment risk for a tool that generates project infrastructure.
The repository has three stars and no forks or watchers, indicating limited external adoption or review. Popularity is only supporting evidence, so this modestly reinforces the maintenance concern rather than deciding the verdict.
Composer build tooling is present, but no security scanning tooling is configured. For a package that installs and generates Docker configuration, this is a transparency and maintenance gap, though not a severe risk by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.