The package is small and clearly tied to its repository, with a license, README, and release notes. The license wording differs from the detected file, while no security policy and limited recent activity reduce confidence in ongoing maintenance.
67%
Total Score
75
79
75
A license file is present in both the artifact and repository, but the manifest declares GPL-2.0+ while the detected file is GPL-2.0; that mismatch warrants checking the intended licensing terms.
The package has 11 releases since December 2017, but none in the last 12 months; its latest registry release was about 20 months before collection, indicating a meaningful maintenance slowdown.
There were no commits or active maintainers in the three months before collection, which is a caution for ongoing fixes even though the repository was pushed earlier in 2026.
Composer build tooling is present, but no security scanning tool was detected; this is a modest transparency and maintenance gap rather than evidence of unsafe behavior.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6 || ^7 | — | — |
typo3/cms-core Version ^12 || ^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.