This release appears usable and reasonably healthy for dependency adoption: it is non-deprecated, stable, actively released, backed by a non-archived organization-owned repository, and includes a substantial README, tests, CI, and release workflows. The main risks are the package's young 79-day history, extreme concentration of commits in one contributor despite a second active contributor, absent security policy, and incomplete GitHub Actions permission hardening; these warrant review before relying on it for critical infrastructure but do not indicate abandonment or an otherwise unfit package.
78%
Total Score
88
50
83
80
The package declares 12 runtime dependencies for a CLI that integrates Laravel, Composer, prompts, HTTP, filesystem, and process functionality; this is a meaningful dependency surface to maintain, but it is consistent with the described installer role.
The package is young at 79 days, which limits demonstrated longevity, but 26 releases in that period with a median interval of about 21 minutes shows very active development rather than abandonment.
Two contributors were active, but one made 46 of 47 commits, creating substantial maintainer concentration. The organization-owned repository provides some ability to hand off maintenance, so this is a caution rather than a severe risk.
The repository has zero stars, forks, and watchers, indicating little visible adoption or external validation; popularity is only supporting evidence, so this lowers confidence more than it determines health.
Composer is used as the build tool, but no security scanning tools were detected. Build tooling is present; the missing security automation is a modest supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^13.0 | — | — |
laravel/prompts Version ^0.3 | — | — |
symfony/process Version ^8.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/events Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.