Its README and small dependency set make the command-line tool easy to assess and install. The repository is not archived and the release is licensed, but testing and long-term maintenance evidence remain limited.
67%
Total Score
100
79
75
The package is 203 days old with 8 releases, but the latest release was about 5 months ago and the release intervals are highly concentrated, giving limited evidence of sustained maintenance.
Composer is used for builds, but no security-scanning tooling is present, leaving a meaningful repository hygiene gap for a young package.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
Version v0.0.9 is not a prerelease, but it remains below 1.0, so compatibility and project maturity are less established than for a stable-major release.
No GitHub Actions workflows were present, so there were no workflow hazards to flag; this also provides no automated CI or release assurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.