The MIT license and exact repository match make its provenance clear. Missing security policy and scanning provide little assurance for a workspace automation tool.
18%
Total Score
0
63
75
Packagist marks the entire package as abandoned, with no distinct replacement package. This is a direct warning against taking a new dependency on it.
The last release was in September 2019, and there have been no releases in about seven years. That indicates the package is effectively abandoned for new maintenance.
The repository had zero commits and zero active maintainers in the last three months, consistent with the multi-year release gap and indicating no current maintenance capacity.
The project uses Composer, but it has no security scanning tools. For a tool that installs and configures software, that leaves a meaningful security-hygiene gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities in a package that runs system configuration commands.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.0 | — | — |
symfony/console Version ^4.0 | — | — |
symfony/process Version ^4.0 | — | — |
symfony/filesystem Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.