The package includes a substantial README, repository tests, and a small runtime dependency set. A single maintainer, missing security policy, and an install-time script leave limited operational and publishing resilience.
54%
Total Score
50
75
50
The package runs post-install and post-update scripts, which can complicate adoption and increase installation-time trust requirements even though no other signal here shows malicious behavior.
Only one registry account has publishing access, creating limited release continuity if that maintainer becomes unavailable; the linked repository is also user-owned rather than organization-backed.
All four releases were published within roughly two hours, and there have been no further releases across the package's 198-day age; this suggests an immature or abandoned release pattern.
The repository recorded zero commits and zero active maintainers during the last three months, which is weak evidence of ongoing maintenance for a package released only months ago.
The repository has zero stars, forks, and watchers after 198 days, providing little evidence of external adoption or review; this is supporting maturity evidence rather than a standalone failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^6.0|^7.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.