This is a generally healthy release with a long package history, four releases in the last 12 months, a stable major version, current repository activity, tests, a clear README, an MIT license, and no deprecation or archived-repository indicators. The main concerns are maintenance concentration in one contributor, absence of repository security scanning and a security policy, and a publish workflow with top-level write permissions; these merit review but do not outweigh the package's active development and substantial project structure.
82%
Total Score
75
50
94
80
The package declares 24 runtime dependencies, including several Symfony, Doctrine, and extension requirements. This is a meaningful integration surface and increases compatibility and maintenance burden, but the dependencies are explicit rather than hidden.
The repository owner is a GitHub User rather than an organization, so there is no provided organization-backing evidence to offset the concentrated contributor activity.
One contributor made all 6 commits in the last 3 months, giving a 100% top-contributor share. This creates a genuine continuity risk because the project is user-owned rather than organization-backed.
Composer is used as a build tool, but no security scanning tool is configured. The absence of scanning is a hygiene gap, though it is not evidence of a malicious package.
The repository has no SECURITY.md or other security policy, leaving vulnerability reporting and disclosure expectations unspecified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
twig/twig Version ^3.14 | — | — |
doctrine/orm Version ^3.6 | — | — |
symfony/mime Version ^7.4 | — | — |
symfony/yaml Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.