Risky to adopt: the project has had no release or commit activity for about 2 years and 5 months after a brief burst of four releases. Its tiny three-file tree and missing README leave little evidence of ongoing maintenance or guidance, despite the repository being active rather than archived.
42%
Total Score
0
38
50
All four releases arrived within a very short period in March 2024, followed by no releases in about 2 years and 5 months. This strongly suggests the package may be abandoned or incomplete.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long gap since the latest release and providing no evidence of current maintenance.
A post-create-project-cmd script runs during project creation, making installation behavior more consequential; the available signal does not show that this script is documented or tested.
The package and repository each contain only three files: .gitignore, composer.json, and docker-compose.yml. That may fit a minimal stack definition, but it provides little transparency about implementation, documentation, or project maturity.
The release has no README, tests, or changelog, although the exact version has GitHub release notes and repository GitHub Releases are used. The release note link is a modest positive, but the missing README is a real usability and transparency gap for a development stack.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.