The package is clearly licensed and backed by an organization, with a stable 1.0.0 release and no deprecation. Its minimal skeleton structure is consistent with its purpose, but there has been no new release or repository activity for nearly four years, and it has no security policy.
52%
Total Score
83
72
75
There is only one release, published nearly four years ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance or compatibility work.
A post-create-project-cmd script runs during project creation. This is relevant install-time behavior and deserves review, but the signal does not show that it is unsafe or unusually broad.
There are no open issues or pull requests and no activity in the last month. For a tiny skeleton this is not inherently problematic, but it adds no evidence of active stewardship.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no independent adoption or maintenance signal.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are configured, leaving a modest transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.