SBOMinator CLI
54%
Total Score
caution
No releases or commits since March 2025, with a tiny user base and broad workflow permissions.
There were zero commits and zero active maintainers in the last three months. Combined with the March 2025 last push, this is the strongest abandonment concern.
The release declares six runtime dependencies, including three packages in the same project namespace. This is a meaningful dependency surface for a small CLI, though the signal does not show excessive or suspicious breadth.
The package is 573 days old but has only three releases, all clustered around March 2025, with no releases in the last 12 months. This indicates a young project whose maintenance has stopped rather than an established steady cadence.
The repository has one star, zero forks, and three watchers. Low adoption is not decisive for a niche CLI, but it provides little external evidence of maturity or broad review.
Composer is used for builds, but no security-scanning tool was detected. That is a transparency and maintenance gap, although it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
minicli/minicli Version ^4.2 | — | — |
sbominator/sbom-lib Version ^0.5.0 | — | — |
minicli/command-help Version ^1.0 | — | — |
sbominator/scaninator Version ^0.1.2 | — | — |
sbominator/transformatron Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.