A clear MIT license, usable README, repository tests, and SECURITY.md provide useful transparency. No release or commit activity has appeared since March 2021, making long-term compatibility uncertain.
48%
Total Score
0
100
78
83
The package has had 8 releases, but its latest release was on March 18, 2021, with none in the last 12 months. More than five years without a release materially increases abandonment and compatibility risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and leaving current maintenance capacity unproven.
The package runs post-install and post-update Composer scripts. This is relevant for a command-line setup tool and adds installation complexity, but the signal alone does not show harmful behavior.
The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible adoption reinforces the uncertainty created by the long inactivity period.
Composer is used for builds, but no repository security-scanning tool was detected. This is a modest transparency gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mnapoli/silly Version ~1.1 | — | — |
symfony/process Version ~2.7|~3.0|~4.0|~5.0 | — | — |
nategood/httpful Version ~0.2 | — | — |
tightenco/collect Version ~5.3|^6.0|^7.0 | — | — |
illuminate/container Version ~5.3|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.