Clear documentation, tests, MIT licensing, and a tiny runtime dependency footprint reduce adoption friction. The organization-owned repository and matching package source add traceability, but its install-time script warrants care.
42%
Total Score
50
100
71
50
The package has only two releases, with the latest published over five years ago and none in the last 12 months. This is strong evidence of stalled maintenance.
There were zero commits and zero active maintainers in the last three months, reinforcing the risk that development has stopped.
The post-create-project-cmd script runs during installation, adding execution behavior that consumers should understand before adoption, although this alone is not evidence of a severe problem.
Composer is used for builds, but no security scanning tooling is present. This is a modest transparency and maintenance gap, not a standalone adoption blocker.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This matters more for a deployment tool that can affect remote systems.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.