Tests, an MIT license, and organization-backed ownership provide useful foundations. The package has no security policy, and its workflow actions are not pinned, leaving avoidable maintenance and build-integrity gaps.
55%
Total Score
50
72
75
There were zero commits and zero active maintainers in the last three months. Combined with the roughly seven-month-old last push, this is the strongest evidence that maintenance has stalled.
The package has only two releases, both published about seven months ago and about two minutes apart, with no later release activity. This is limited evidence of sustained maintenance.
Two issues remain open, with no issues or pull requests opened or closed in the last month. This shows unresolved work and no recent issue-management activity, though the small project size limits how strongly it should be weighted.
The repository has zero stars, forks, and watchers. This is weak supporting evidence rather than a verdict, since a small package can still be healthy if actively maintained.
The repository uses Make and Composer, but no security-scanning tools are detected. Build tooling is present, while the missing scanning coverage is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.0 | ^8.0 | — | — |
symfony/config Version ^7.0 | ^8.0 | — | — |
symfony/console Version ^7.0 | ^8.0 | — | — |
symfony/http-kernel Version ^7.0 | ^8.0 | — | — |
symfony/dependency-injection Version ^7.0 | ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.