The package has clear usage documentation and a stable release line. Its small recent contribution base and lack of repository security controls leave maintenance and oversight dependent on one contributor.
74%
Total Score
67
93
50
One contributor made all one recent commit, concentrating current maintenance capacity. Organization ownership provides some handoff potential, but no second active contributor is shown.
Only one commit was recorded in the last three months, indicating limited recent development activity despite the regular registry release history. This is a maintenance caution, not evidence of abandonment by itself.
Composer build tooling is present, but no security-scanning tooling was detected. That leaves repository-level security oversight less transparent than it could be.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. This is a transparency and response-readiness gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.4 | — | — |
symfony/console Version ^7.4 | — | — |
contao/core-bundle Version ^5.7 | — | — |
symfony/http-kernel Version ^7.4 | — | — |
symfony/event-dispatcher Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.