Usable with caveats: it is a very new pre-1.0 package maintained by one contributor, so long-term stability and continuity are unproven. The repository is active, tested, licensed, and uses basic security and CI tooling, but its short history warrants caution for production use.
62%
Total Score
67
86
88
The package and repository are owned by the same individual account, confirming direct ownership but providing no organizational handoff or support structure.
The package is only 45 days old with three releases, all published within a very short interval, so there is not yet enough history to demonstrate sustained maintenance or release stability.
One contributor made all 10 commits during the measured period, creating a meaningful continuity risk if that maintainer becomes unavailable.
The repository has no security policy, which leaves vulnerability-reporting expectations unclear; this is a transparency gap, though the project does use Dependabot.
Version v0.2.1 is not a stable-major release, indicating an evolving API and a higher likelihood of breaking changes than a mature 1.x package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^7.4|^8.0 | — | — |
illuminate/console Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/filesystem Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.