Tests, a clear README, and an MIT license improve day-to-day adoption. The clean workflow audit is offset by three unpinned actions and no security policy; pin v1.0 only with an upgrade plan.
55%
Total Score
25
78
50
This is the package's only release, published over five years ago, with no releases in the last 12 months. That substantially increases the risk of compatibility drift and abandonment.
There were no commits and no active maintainers in the last three months. Combined with the single old registry release, this points to weak current maintenance capacity.
The registry namespace and repository owner are the same individual, showing clear ownership but no organizational backing or broader maintenance structure.
The repository has zero stars and forks and one watcher, providing little community validation. Popularity is supporting evidence rather than a verdict, so this is a modest concern only.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^5.2 | — | — |
symfony/yaml Version ^5.2 | — | — |
symfony/config Version ^5.2 | — | — |
symfony/http-kernel Version ^5.2 | — | — |
symfony/http-foundation Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.