The package is clearly tied to its repository, has repository tests, readable documentation, and an MIT license. Its automation uses nine unpinned actions, and no security policy or scanning is present, adding maintenance and supply-chain hygiene concerns.
42%
Total Score
25
75
50
The package is 1036 days old, with 13 releases but none in the last 12 months; its latest release was nearly three years ago. This is strong evidence of abandonment risk.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of current maintenance.
Only one registry publishing maintainer is listed. The linked repository is also owned by a user account, so there is no organization backing shown to compensate for the thin maintainer base.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though the package's small demo scope limits its weight.
Version 0.1.3 is a non-prerelease release but remains below 1.0, so its API and behavior may be less mature than a stable-major package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.3 | — | — |
symfony/console Version ^6.3 | — | — |
symfony/translation Version ^6.3 | — | — |
symfony/twig-bundle Version ^6.3 | — | — |
symfony/framework-bundle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.