Documentation, tests, and a complete source tree make integration easier, while organizational backing and regular releases add useful reassurance. Pin this version only after checking why commit activity is currently absent.
68%
Total Score
67
88
67
There were no commits and no active maintainers in the last 3 months. This is a meaningful maintenance concern and conflicts with the recent release and pull-request activity.
The package uses a post-autoload-dump lifecycle script. This is common Composer behavior, but it adds install-time execution that consumers should account for.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap rather than evidence of an unsafe release by itself.
No repository security policy was found. For a maintained library this reduces disclosure transparency, although the package's tests, licensing, and release history provide some compensating project hygiene.
Version v0.2.20 is not a stable major release, so compatibility expectations are lower than for a 1.x package. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.4 | — | — |
symfony/serializer Version ^7.4 | — | — |
symfony/http-kernel Version ^7.4 | — | — |
api-platform/openapi Version ^4.1 | — | — |
api-platform/metadata Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.