The package includes a substantial test suite, a matching Apache-2.0 license, and a repository that is actively being published. It has no security policy or security-scanning tooling, and its very recent 0.x history leaves long-term maintenance unproven.
68%
Total Score
100
100
79
75
The package is only 1 day old with five releases and a median interval of about 9 hours, showing active initial iteration but providing almost no long-term maintenance evidence.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest security-process gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
Version 0.1.7 is not a stable-major release, so its API and behavior may still change even though it is not marked as a prerelease.
No GitHub Actions workflows were analyzed, so there are no workflow hazards to report, but this also provides no evidence of automated repository checks.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.4 || ^8.0 | — | — |
symfony/routing Version ^7.4 || ^8.0 | — | — |
symfony/validator Version ^7.4 || ^8.0 | — | — |
symfony/serializer Version ^7.4 || ^8.0 | — | — |
symfony/property-info Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.