Tests, release notes, and a clear MIT license provide useful transparency. The missing security policy and install-time script add smaller operational concerns; pin this version if reproducibility matters.
69%
Total Score
50
88
50
The package runs a post-autoload-dump install-time script, which adds execution during dependency installation and warrants some supply-chain caution.
The package has existed since March 2015 with 35 releases, but only one release appeared in the last 12 months, indicating a slower recent cadence despite long history.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of slowed current maintenance; the recent 4.4.1 release partly offsets but does not remove this concern.
Composer and Box provide build tooling, but no security scanning tools were detected, leaving a modest assurance gap.
The repository has no security policy, making vulnerability reporting and disclosure expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 || ^8.0 | — | — |
psr/container Version ^2.0 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
symfony/finder Version ^7.4 || ^8.0 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.