Organization backing, tests, and clear licensing provide useful maintenance context. There is no published security policy, and the repository’s very small audience limits independent oversight.
65%
Total Score
83
79
75
The package has 10 releases but none in the last 12 months, with the latest released in April 2021. A repository push in January 2024 provides some compensating evidence, but registry maintenance has clearly slowed.
There are no open issues or pull requests, and no recent activity is recorded; this is consistent with a quiet project but does not establish active maintenance.
The repository has only 2 stars, 0 forks, and 1 watcher, indicating limited independent adoption and oversight. Popularity is supporting evidence rather than a health verdict.
The project uses Composer for builds, but no security-scanning tools were detected. The missing scanning coverage is a modest transparency gap.
No security policy was found in the repository, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/cache Version ^1.8 | — | — |
webmozart/assert Version ~1.3 | — | — |
symfony/validator Version >3.4 | — | — |
php-http/discovery Version ^1.0 | — | — |
doctrine/annotations Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.