Healthy and reasonable to adopt, with a small maintenance caveat. It has frequent recent releases, active development, tests, clear ownership, and safe workflow permissions, but all recent commits come from one contributor and the repository has no security policy.
78%
Total Score
88
100
89
90
One contributor made all 30 commits in the last three months, creating a real continuity risk. Organization ownership provides some ability to hand maintenance off, but no second active contributor is shown.
The repository has zero stars, forks, and watchers, so there is little external adoption evidence. For a package only 84 days old, this is a maturity limitation rather than a decisive health problem.
Composer build tooling is present, but no security scanning tools were detected; this is a modest process gap rather than evidence of abandonment.
No repository security policy was found, reducing transparency for vulnerability reporting, although this does not by itself indicate unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^7.4 || ^8.0 | — | — |
psr/container Version ^2.0 | — | — |
componenta/cqrs Version ^4.0.0 | — | — |
componenta/config Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.