The source tree includes tests, a changelog, release notes, and clear organization ownership. Pin this exact version only if you can accept its unproven maintenance track record.
70%
Total Score
75
100
86
75
This is the package's first release, published less than 1 hour ago, so there is no track record for release consistency or long-term maintenance.
No commits or active maintainers were observed in the prior 3 months, but the package is less than 1 hour old, so this is better interpreted as limited history than as collapsed maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, which reduces transparency for reporting vulnerabilities and handling maintenance issues.
Both workflows use unpinned actions, and the audit found a high-confidence medium-severity secrets-inherit issue; there are no dangerous untrusted triggers or write-wide top-level permissions, which limits the impact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
symfony/console Version ^6.4.10 || ^7.1.3 | — | — |
psr/http-factory Version ^1.0.2 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.