The package is clearly identified, MIT-licensed, and has a usable README with no install-time scripts. Its single-maintainer project has had no commits for seven years, and minimal adoption plus no security policy increase abandonment risk.
38%
Total Score
25
75
75
The latest release was on August 19, 2019, and there have been no releases in the last seven years. Only four releases exist, so ongoing maintenance is not evident.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the seven-year release gap and strong abandonment risk.
One registry maintainer is reasonable for a personal project, but it provides little maintenance redundancy when the repository also shows no recent activity.
The repository has one star, no forks, and no watchers. Popularity is only supporting evidence, but these values provide little evidence of an active user or contributor community.
The repository has no security policy or security-scanning tooling. This is a secondary transparency gap for a small CLI, but it adds little support for dependable long-term maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.4|^1.5|^1.6 | — | — |
symfony/console Version ~3.0|~4.0 | — | — |
symfony/process Version ~3.0|~4.0 | — | — |
tecnickcom/tcpdf Version ^6.2 | — | — |
guzzlehttp/guzzle Version ~5.0|~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.