Healthy and actively maintained, with strong documentation, tests, and frequent recent releases. Depend on it with some caution because all recent commits come from one contributor and the release workflow has write permissions without a security policy.
78%
Total Score
88
100
94
63
The package uses post-install and post-update Composer scripts. These increase installation-time activity and deserve review before adoption, although the signal does not show that the scripts are unsafe.
All 90 commits in the last three months came from one contributor, giving the project a high single-person dependency despite its strong activity level.
The repository has 3 stars and no forks or watchers. This is limited adoption evidence, but popularity is supporting evidence and does not outweigh the strong recent maintenance signals.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
One workflow, release-please.yml, has top-level write permissions, while the other is read-only. Write access is understandable for automated releases but grants broader automation authority than a fully restricted setup.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
contao/image Version ^1.2 | — | — |
symfony/yaml Version ^7.3 | — | — |
psr/container Version ^2.0 | — | — |
symfony/asset Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.