The package is licensed, has a README, and its repository still matches the package. Its tiny three-star project and lack of security scanning add little evidence of ongoing support.
40%
Total Score
0
78
75
The latest release was in October 2018, about 7 years and 11 months ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, although the package is not marked deprecated.
The repository had zero commits and zero active maintainers in the last 3 months, consistent with the long release gap. No newer activity is provided to offset the concern.
The repository has 3 stars, 0 forks, and 1 watcher, providing little community evidence or backup support. Low popularity alone is not decisive, but it offers no compensation for the long inactivity.
Composer is used for builds, but no security scanning tools are present. That is a modest transparency and upkeep gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response practices undocumented. This compounds the maintenance concern for a package that executes remote SSH commands.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fzaninotto/faker Version ^1.4 | — | — |
illuminate/support Version ^5.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.