It has a clear MIT license, a substantial README, and broad automated tests. The small one-person project has no commits in three months and leaves both workflow actions unpinned.
64%
Total Score
0
81
50
The repository recorded no commits and no active maintainers during the last three months, materially increasing the risk that defects or compatibility problems will go unaddressed.
Five releases arrived over roughly 10 days, showing an initially active release cycle, but the history does not demonstrate sustained maintenance beyond that burst.
The repository has only 2 stars and no forks or watchers. Popularity is not decisive, but this provides little supporting evidence of adoption or external review.
Composer and Box build tooling are present, but no security scanning tools were detected. For a deployment tool handling SSH and remote execution, that is a meaningful hygiene gap.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for a tool that manages deployment credentials and remote operations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.41 | — | — |
guzzlehttp/guzzle Version ^7.10 | — | — |
phpseclib/phpseclib Version ^3.0 | — | — |
laravel-zero/framework Version ^12.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.