Usable with caveats: this is a well-documented, licensed package with matching organization-backed source and repository tests, but it is only one day old with four rapid releases and no established commit history. Its single workflow lacks explicit token permissions and the repository has no security policy.
68%
Total Score
83
100
78
75
The package is only 1 day old and has four releases, with a median interval of about 10 hours. This shows active initial iteration but provides almost no long-term maintenance evidence.
There were no commits or active maintainers recorded in the last 3 months, so there is no established maintenance track record; the package's one-day age limits how strongly this should be interpreted.
The repository has only 1 star, 0 forks, and 1 watcher. This provides little external validation, though low popularity alone is not evidence that a small new package is unsafe to adopt.
Composer is used as a build tool, but no security scanning tooling is detected. The missing scanning layer is a modest transparency and maintenance concern.
No repository security policy is present, leaving vulnerability-reporting expectations unclear for a package that runs development environment commands.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.0 || ^8.0 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
symfony/process Version ^7.0 || ^8.0 | — | — |
symfony/filesystem Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.