The package has only one release in the last year and no recent commit activity, so maintenance capacity is limited. Tests, release notes, and organization backing provide useful reassurance.
65%
Total Score
67
100
83
50
Composer post-install and post-update scripts add execution during dependency operations. They are a modest supply-chain exposure, although no other provided signal shows these scripts are malicious or unusually broad.
The package has been published for about four years with nine releases, but only one release appeared in the last year. That suggests slower maintenance for a library with ongoing compatibility needs.
The repository recorded zero commits and zero active maintainers in the last three months. Although the latest release was recent, the absence of recent development activity raises abandonment risk.
There are no open issues and one open pull request, but no issues or pull requests were merged in the last month. This provides little evidence of active community maintenance.
The repository has one star and one fork, indicating a very small external user base. Popularity is supporting evidence only, so this modestly limits visible adoption signals rather than making the package unfit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11|^2.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
symfony/serializer Version ^7.1|^8.0 | — | — |
symfony/http-kernel Version ^7.1|^8.0 | — | — |
symfony/property-info Version ^7.1|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.