The package includes tests, a changelog, a matching repository, and a clear MIT license. Maintenance has gone quiet, with no release in the past 12 months and no commits in the past 3 months; it also lacks a security policy and scanning.
65%
Total Score
50
100
88
75
Only one registry account has publishing access, leaving a thin publishing base; the linked repository is also owned by an individual rather than an organization.
The repository is owned by a user account rather than an organization, so there is no observed organizational backing to offset the small maintainer base.
The package has 16 releases since February 2021 and a latest release in June 2025, but it has had no releases in the past 12 months, indicating slowed maintenance.
There were no commits and no active maintainers in the past 3 months, which is evidence of currently quiet development despite the June 2025 release.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-process gap in the source project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
symfony/cache Version ^4.4 || ^5.4 | — | — |
symfony/config Version ^4.4 || ^5.4 | — | — |
symfony/console Version ^4.4 || ^5.4 | — | — |
symfony/http-kernel Version ^4.4 || ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.