The package has clear documentation, a changelog, and release notes for this version. Installation uses no lifecycle scripts, but the repository has no security policy and recent work comes from one contributor.
73%
Total Score
63
94
75
The package and repository are owned by the same individual account, which supports source identity but provides less organizational maintenance depth than an organization-backed project.
All recent commit activity came from one contributor, leaving maintenance dependent on a single active developer; the repository is user-owned rather than organization-backed.
Only one commit was recorded in the last three months, so current development activity is limited even though a recent release was published.
Composer is used for builds, but no security-scanning tooling was detected, leaving automated coverage for dependency or code issues limited.
The repository has no security policy, which makes vulnerability reporting and expected security handling less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.3 || ^4.0 | — | — |
symfony/finder Version ^5.4 || ^6.0 || ^7.0 | — | — |
contao/core-bundle Version ^4.13 || ^5.0 | — | — |
symfony/filesystem Version ^5.4 || ^6.0 || ^7.0 | — | — |
symfony/http-kernel Version ^5.4 || ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.