A changelog, repository tests, and release notes improve transparency, while the package has no install-time scripts. Workflow actions are unpinned, and the repository lacks both a security policy and security scanning.
82%
Total Score
83
88
75
One contributor made about 73% of recent commits, which creates some concentration risk. Two additional contributors remained active, and the organization-owned project provides some handoff capacity.
The repository has 0 stars and 1 fork, indicating limited public adoption. Popularity is supporting evidence rather than a decisive health measure, so this is only a minor concern.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning reduces assurance about automated security oversight.
The repository has no SECURITY.md or other security policy. This is a transparency and vulnerability-reporting gap, although it does not by itself indicate abandonment.
The single workflow was fully analyzed with no injection or high-severity findings, but both action references are unpinned. Unpinned actions are a mild reproducibility and workflow supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
21torr/cli Version ^1.2.4 | — | — |
symfony/cache Version ^8.0 | — | — |
symfony/clock Version ^8.0 | — | — |
symfony/config Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.