The package includes tests, release notes, a clear MIT license, and Dependabot-backed tooling. Its small release history, missing security policy, and unpinned workflow actions leave less maintenance and build transparency than mature dependencies.
62%
Total Score
75
83
50
A post-install command runs during installation. The signal does not show what it does, so this adds a modest supply-chain review concern without proving harmful behavior.
Only 3 releases have been published over about 17 months, with 1 release in the last 12 months; this indicates a small and relatively slow release history.
There were no commits and no active maintainers in the last 3 months, indicating a recent maintenance pause; the non-archived repository and release history provide only partial compensation.
The repository name does not match the package name and its README does not mention the package, so the link is less transparent even though the repository path otherwise resembles the package.
The repository has 0 stars, 0 forks, and 1 watcher. This is weak supporting evidence, but popularity is not required for a small stable package and does not outweigh its maintenance signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.3 || ^7.0 | — | — |
symfony/config Version ^6.3 || ^7.0 | — | — |
symfony/http-kernel Version ^6.3 || ^7.0 | — | — |
atoolo/rewrite-bundle Version ^1.2 | — | — |
atoolo/resource-bundle Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.