It has a clear license, a focused dependency set, repository tests, recent releases, and organization backing. Maintenance is concentrated in one recent contributor, and all six workflow actions are unpinned; the missing security policy adds a smaller transparency gap.
68%
Total Score
67
100
100
75
One contributor made all nine recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown to share current maintenance.
The repository recorded nine commits in the last three months, but all activity came from one active maintainer, limiting evidence of resilient maintenance capacity.
No repository security policy was found, leaving reporting and disclosure expectations undocumented.
The workflow audit completed cleanly with no dangerous triggers or audit findings, but all six action references are unpinned. That weakens build reproducibility and supply-chain hygiene without making the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
symfony/config Version ^6.4 || ^7.4 | — | — |
symfony/routing Version ^6.4 || ^7.4 | — | — |
contao/core-bundle Version ^5.7 | — | — |
symfony/http-kernel Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.