The package has a clear GPL license, matching repository, and usable README. Install-time scripts, no security policy, and a single maintainer add operational and transparency concerns.
42%
Total Score
25
79
67
The latest release was nearly two years ago, and there were no releases in the last 12 months despite 136 releases overall. The earlier rapid cadence does not compensate for the prolonged current inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the abandonment risk indicated by the release history.
post-install-cmd and post-update-cmd scripts run during Composer operations, adding maintenance and review burden because package installation can execute project-defined behavior.
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so there is little visible publishing redundancy if that maintainer becomes unavailable.
Composer is used as a build tool, but no security-scanning tools were detected. That weakens documented security hygiene without independently making the release unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
anzubko/swf-core Version * | — | — |
symfony/validator Version ^7.1.5 | — | — |
symfony/serializer Version ^7.1.5 | — | — |
symfony/property-access Version ^7.1.4 | — | — |
phpdocumentor/reflection-docblock Version ^5.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.