Usable with caveats: the package is correctly backed by an active, matching repository and has clear licensing, build tooling, and recent releases. However, it has only two releases, no tests, no commits in the last three months, and a single publisher, so long-term maintenance capacity is not yet demonstrated.
60%
Total Score
63
100
83
80
There were zero commits and zero active maintainers in the last three months, despite a recent release. This is the strongest maintenance concern because ongoing development capacity is not demonstrated.
Only one registry account has publishing access. This is a modest resilience concern, and the repository owner is an individual rather than an organization, so there is no provided organizational backing to compensate for the thin publisher base.
A README and changelog are present, but neither the package nor repository contains tests. For a framework integration bundle, this leaves behavior and regression coverage less transparent.
The package is only 146 days old with two releases and a median interval of 146 days, so there is limited evidence of sustained release maintenance.
The repository has zero stars, forks, and watchers. This does not prove poor quality, but it provides no supporting evidence of adoption or community visibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.2 | — | — |
monolog/monolog Version ^3.0 | — | — |
contao/core-bundle Version ^5.7 | — | — |
symfony/http-kernel Version ^7.2 | — | — |
symfony/http-foundation Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.