The implementation is small and transparent, with a matching repository, MIT licensing, and a usable README. Its maintenance and security evidence is weak, so long-term dependency risk remains significant.
46%
Total Score
50
100
78
75
This is the package's only release, published in July 2019, with no releases in the following seven years. That strongly limits evidence of continued maintenance, although the package is not marked deprecated.
There were no commits or active maintainers in the last three months, and the repository has not been updated since July 2019. For a dependency, that is substantial evidence of possible abandonment.
The repository has only 1 star, 1 fork, and no watchers. Low popularity is not decisive for a small utility, but it provides little independent evidence of community scrutiny or support.
Composer is used for the build, but no security-scanning tool is configured. The missing scanner is a hygiene weakness, though it is less serious for this small package than the prolonged inactivity.
The repository has no security policy. This reduces transparency about vulnerability reporting and response, especially because there is no visible recent maintenance to compensate.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
technodelight/shell-exec Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.