It has solid tests, documentation, a matching repository, and recent activity from two contributors. The prerelease status, short project history, missing security policy, and unpinned workflow actions warrant extra care before production adoption.
68%
Total Score
83
78
67
The package is only 38 days old with three releases and a median interval of about 14 days. This shows recent activity but provides limited evidence of long-term maintenance.
Two contributors are active, but one accounts for about 79% of recent commits. The second contributor provides some continuity, while the concentration still creates moderate succession risk.
The repository has no stars, forks, or watchers. For a package only 38 days old this is limited supporting evidence rather than a decisive health problem.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning coverage is a minor transparency and maintenance gap.
The repository has no security policy. This does not show unsafe code, but it leaves vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
coolms/dtmpl Version ^2.1 | — | — |
symfony/config Version ^8.0 | — | — |
symfony/http-kernel Version ^8.0 | — | — |
symfony/dependency-injection Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.