The repository has solid documentation, tests, a changelog, and a matching MIT license. Its small audience, absent recent commits, missing security policy, and broad unpinned workflow actions leave meaningful maintenance and build-hygiene concerns.
70%
Total Score
50
100
89
50
The registry namespace and repository owner are both associated with the same individual account context, rather than an organization-backed project. This does not invalidate the package, but it offers limited evidence of institutional maintenance capacity.
There were 0 commits and 0 active maintainers in the last three months, despite the package having released recently enough to show an established history. This is a concrete sign that maintenance may have slowed or stopped.
The repository has 3 stars, 1 fork, and 1 watcher, indicating a very small user and contributor base. Popularity is supporting evidence rather than a verdict, but this provides little external maintenance capacity.
The repository uses Composer for builds, but no security-scanning tools were detected. That weakens automated security hygiene without proving a defect in the release.
No repository security policy was found. This reduces transparency about vulnerability reporting and response expectations, though it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.