The package has extensive documentation, tests, a changelog, and a clear matching source repository. Its workflow has a low-confidence cache warning and unpinned actions, while security-policy coverage is absent.
62%
Total Score
50
50
88
75
There have been zero commits and zero active maintainers in the last three months, indicating that development activity has stopped recently.
The package has 17 runtime dependencies, including several framework, storage, image-processing, and external-service integrations. This is a meaningful maintenance surface, though the signal does not show an abnormal or clearly unsafe dependency pattern.
One registry account publishes the package. That is consistent with the repository being owned by the same individual, but it still indicates a narrow publishing base.
The project has a long history with 55 releases and a typical historical interval of about 25 days, but it has had no release in the last 12 months. The recent pause is a maintenance concern despite the strong history.
Only one issue and no pull requests are open, but there has been no issue or pull-request activity in the last month. This is consistent with a quiet project but provides little evidence of ongoing support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^4.4 || ^5.1 || ^6.4 || ^7.2 | — | — |
tinify/tinify Version ^1.5 | — | — |
symfony/dotenv Version ^4.4 || ^5.1 || ^6.4 || ^7.2 | — | — |
symfony/finder Version ^4.4 || ^5.0.7 || ^6.4 || ^7.2 | — | — |
monolog/monolog Version ^1.22 || ^2.1.1 || ^3.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.