It has a clear MIT license, useful documentation, repository tests, and release notes for this version. The organization-backed repository had no commits in the last three months, and it lacks a security policy and scanning tools.
65%
Total Score
75
83
50
A post-install command runs during installation, adding execution surface beyond ordinary file installation; the signal provides no evidence that the script is malicious or unusually risky.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of slowed maintenance despite the recent release.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest verification gap.
The linked repository has no security policy, making the process for reporting and handling vulnerabilities unclear.
Version 0.4.1 is not a stable-major release, which signals API-change risk, but it is a normal release rather than a prerelease and recent versions have not been prereleases.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/serializer Version ^3.23 | — | — |
symfony/console Version >=5.4 | — | — |
league/tactician Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.