Healthy and actively maintained, with strong documentation, testing, and recent release evidence. Review its install-time scripts and small contributor base before adopting it in a critical project.
86%
Total Score
83
100
94
80
The package defines post-install and post-update Composer scripts, which increase the trust required at dependency installation and update time even though this signal alone does not establish malicious behavior.
Commit activity is concentrated in one contributor at about 65%, but a second contributor supplied about 35% of recent commits, reducing the risk compared with a single-contributor project.
The repository has only 3 stars and no forks, so external adoption evidence is limited. The package is young and its strong recent release and commit activity provide more relevant maintenance evidence.
Seven workflows declare read-only permissions and none declare top-level write access. One changelog workflow lacks top-level permissions, leaving a modest configuration gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.4||^7.0||^8.0 | — | — |
sebastian/diff Version ^7.0 || ^8.0 || ^9.0 | — | — |
symfony/finder Version ^6.4||^7.0||^8.0 | — | — |
composer/semver Version ^3.4 | — | — |
laravel/prompts Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.