The package has a clear README, tests, release notes, and an MIT license, which support adoption. Its workflows are auditable but use six unpinned actions, and no security policy or scanning tool is present.
58%
Total Score
33
100
69
63
Only two releases exist, both published in December 2024, with no release in roughly one year and nine months. That limited and inactive history lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers over the last three months. Combined with the old last release, this is strong evidence that maintenance has stalled.
The package defines a post-create-project-cmd lifecycle script. This adds installation-time behavior that deserves review, though the signal does not show a dangerous command or broad install hook.
The package and repository are consistently owned by the same individual account, so the source relationship is clear. Individual ownership also indicates a relatively narrow maintenance base.
There are two open issues and no issue or pull-request activity in the last month. This is limited evidence of current project attention, though the issue count is small.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.