The package is small and has no security policy or automated security scanning. Organization ownership and a non-deprecated repository provide some accountability, but the pre-1.0 release remains dated.
42%
Total Score
100
100
71
75
Neither the registry metadata nor the package or repository contains a detected license. This creates a material adoption and redistribution concern.
The package has had no release in about 2 years and 9 months, with no releases in the last 12 months. That substantially raises abandonment risk despite eight releases in its initial two-day burst.
Composer is used for builds, but no security scanning tooling is present. That is a modest transparency and maintenance weakness rather than evidence of unsafe behavior.
The repository has no security policy. For a package with no other documented security process, this modestly reduces transparency for reporting and handling vulnerabilities.
Version 0.0.8 is still pre-1.0, so compatibility and maturity are less established. The package is not marked as a prerelease, which provides limited compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version * | — | — |
doctrine/orm Version * | — | — |
guzzlehttp/guzzle Version * | — | — |
symfony/serializer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.