The repository includes tests, a clear MIT license, and a complete workflow audit. Its single-release history, no recorded three-month commit activity, absent security policy, and two unpinned actions leave maintenance and build-integrity evidence thin.
68%
Total Score
75
100
86
67
This is the package's first and only release, published within the collection window, so long-term maintenance and release reliability are not yet demonstrated.
The repository recorded zero commits and zero active maintainers in the last three months. Because the package is newly released, this is not proof of abandonment, but it leaves maintenance capacity unproven.
Composer is used as the build tool, providing expected project tooling, but no security scanning tools were detected, leaving a modest transparency gap.
The repository has no published security policy, so users have no documented reporting path or security-maintenance expectations.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, but both of its two action references are unpinned. That creates avoidable build-integrity exposure without making the package unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/prompts Version ^0.3 | — | — |
symfony/console Version ^7.0|^6.4 | — | — |
symfony/process Version ^7.0|^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.