Healthy and reasonable to adopt, with a short track record. It is actively released, tested, documented, and backed by a matching repository, but all recent commits come from one contributor and one workflow has write permissions.
78%
Total Score
70
100
89
70
The package runs post-install and post-update Composer scripts, adding install-time behavior that warrants review even though no dangerous workflow behavior was detected elsewhere.
Only one registry account has publish access, which is a modest resilience concern; the repository is owned by the same individual rather than an organization that could more readily hand off publishing.
The registry namespace and repository owner match, but the owner is an individual user rather than an organization, so there is no organizational backing to offset the concentrated maintainer base.
The package is only 29 days old with four releases, including a latest release today; this shows active development but leaves little evidence of long-term stability.
All six commits in the last three months came from one contributor, creating a genuine continuity risk with no second active contributor shown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.3 | — | — |
symfony/routing Version ^7.3 | — | — |
contao/core-bundle Version ^5.7 | — | — |
symfony/filesystem Version ^7.3 | — | — |
symfony/http-kernel Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.