Clear documentation, tests, and a matching source repository make adoption easier. Maintenance is still concentrated in one contributor, with only one commit in the last three months and no security policy or scanning.
68%
Total Score
50
81
83
The repository is owned by a user account rather than an organization, so the single-person maintenance evidence is not offset by visible organizational backing.
There have been two releases over about 114 days, with the latest about 78 days after the assessment window began; this is a young but demonstrated release history rather than abandonment.
All recent commits came from one contributor, leaving no demonstrated handoff capacity if that contributor becomes unavailable.
Only one commit was recorded in the last three months, with one active maintainer. For a young package this is limited evidence of ongoing maintenance and lowers confidence in its continuity.
The repository uses Make and Composer, but no security scanning tools were detected. That is a modest supply-chain hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.0|^4.0 | — | — |
symfony/mailer Version ^6.3|^7.0|^8.0 | — | — |
symfony/messenger Version ^6.3|^7.0|^8.0 | — | — |
symfony/scheduler Version ^6.3|^7.0|^8.0 | — | — |
symfony/twig-bundle Version ^6.3|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.