Usable with caveats: the package is licensed, documented, tested, and backed by a recent stable release, with an active unarchived repository. Maintenance is concentrated in one contributor, recent commit activity is light, and the project has little adoption and no security policy.
72%
Total Score
50
89
83
The registry namespace and repository are owned by the same individual account, confirming direct ownership but offering no organizational maintenance redundancy.
One contributor made all 2 recent commits, leaving maintenance dependent on a single individual with no demonstrated handoff capacity.
Only 2 commits were recorded in the last 3 months, which is light activity for a deployment tool and lowers confidence in sustained maintenance.
The repository has 4 stars, 0 forks, and 0 watchers; popularity is only supporting evidence, but these figures provide little external validation for this young project.
Composer build tooling is present, but no security-scanning tools were detected, leaving automated dependency or code security coverage un demonstrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 | — | — |
symfony/dotenv Version ^7.4 | — | — |
aws/aws-sdk-php Version ^3.373 | — | — |
laravel/prompts Version ^0.3.15 | — | — |
symfony/console Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.