The clear MIT license, useful README, release notes, and lack of install-time scripts support straightforward adoption. All four releases arrived within hours and the project has little visible adoption, so sustained maintenance is still unproven.
64%
Total Score
100
78
75
There are four releases, but they were all published within hours and the latest release was about five months before collection. That provides limited evidence of sustained maintenance.
The repository has 7 stars, 1 fork, and 0 watchers. Low adoption is supporting caution about project maturity, though popularity alone is not a health verdict.
Composer is used for builds, but no security-scanning tools are configured. The missing scanning is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy. For a package that integrates workflow and web application code, this leaves vulnerability reporting and response expectations unclear.
v0.0.4 is not a stable major release, so the pre-1.0 API may still change. It is not marked as a prerelease, which partly offsets the maturity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ysh/yflow Version ^0.0.1 | — | — |
webman/console Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.