The project has tests, release notes, a matching repository, and organization backing. Its source remains active, but security documentation and recent registry publishing are limited.
70%
Total Score
88
100
88
67
The package has a long history of 72 releases with a typical interval of about 14 days, but it has had no registry release in the last 12 months. This is a meaningful publishing slowdown, partly offset by recent repository activity.
There were no new or closed issues in the last month and only one pull request was merged, indicating limited recent issue throughput despite continued source activity.
Composer build tooling is present, but no security scanning tools were detected. For a framework with a substantial dependency and release surface, this is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All three workflows were analyzed without untrusted triggers or script injection, but all 13 action references are unpinned and high-confidence findings report unpinned container images; two workflows also install packages outside a lockfile. These are workflow supply-chain hygiene weaknesses, not evidence that the package itself is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atk4/data Version ~6.0.0 | — | — |
nyholm/psr7 Version ^1.6 | — | — |
nyholm/psr7-server Version ^1.0 | — | — |
symfony/filesystem Version ^4.4 || ^5.3 || ^6.0 | — | — |
symfony/http-foundation Version ^4.4 || ^5.3 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.