The repository has no stars and no automated security scanning, limiting external validation. Clear documentation, tests, changelog, and matching MIT licensing provide useful transparency.
55%
Total Score
75
75
100
This package has only one release, published over four years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with prolonged inactivity. The repository is not archived, which is only a limited compensating signal.
The repository has zero stars and zero forks, with only two watchers. Popularity is not decisive, but these counters provide little independent evidence of adoption or community support.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, not evidence that the code is unsafe.
The latest version is 0.0 and is not a stable major release. Combined with the single-release history, this suggests an immature project rather than a mature maintained dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.0 | — | — |
symfony/http-kernel Version ^5.0 | — | — |
symfony/dependency-injection Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.