The package includes consumer documentation, tests, an MIT license, and no install-time scripts. Its release and commit activity stopped about five years ago, while the repository remains unarchived and clearly matches the package.
42%
Total Score
50
75
75
The package has 8 releases but none in the last 12 months, and the latest recorded registry release was about five years ago. This strongly raises abandonment risk despite its earlier release history.
The repository recorded 0 commits and 0 active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance activity.
The project uses Composer and Box for its build, showing a defined packaging process. No security-scanning tooling is reported, which is a modest transparency and hygiene gap.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This matters more for a CLI that handles Forge access tokens, although it is not evidence of unsafe behavior by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^5.1 | — | — |
laravel/forge-sdk Version ^3.6.0 | — | — |
laravel-zero/framework Version ^8.8 | — | — |
nunomaduro/laravel-console-menu Version ^3.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.