Unpinned workflow actions and a missing security policy reduce transparency. The old v0.2 release line and no commits in the last three months make long-term maintenance uncertain, despite a clear README, tests, and a matching repository.
52%
Total Score
67
50
64
50
Only two releases exist, with the latest published in September 2018 and none in the last eight years. This is strong evidence of a stale registry release line, although repository activity provides limited compensation.
Thirteen runtime dependencies, including an older framework-era stack, create meaningful maintenance surface and transitive dependency exposure for this application package.
The package declares a proprietary license and provides no license file, which limits confidence that developers can use it as an open-source dependency.
The package runs post-install and post-update scripts, adding installation-time behavior that deserves review even though no specific harmful action is shown.
The package and repository are owned by a single individual rather than an organization, so there is limited demonstrated institutional backing for continuity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
embed/embed Version ^3.3 | — | — |
symfony/flex Version ^1.0 | — | — |
symfony/yaml Version * | — | — |
nesbot/carbon Version ^1.24 | — | — |
symfony/dotenv Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.