Healthy and suitable to use, with a small maintenance caveat: the project has a long release history, a current stable release, strong repository backing, tests, and security practices. Recent repository activity is very limited and concentrated in one contributor, although organization ownership reduces the abandonment risk.
78%
Total Score
67
100
100
90
All recent commits came from one contributor, creating concentration risk. The organization-owned repository provides some capacity to hand maintenance off, so this is a caution rather than a severe risk.
Only 1 commit from 1 active maintainer was recorded in the last 3 months, which is a meaningful sign of currently thin maintenance activity despite the recent release history.
None of the 7 workflows declares top-level token permissions, which is a workflow-hardening gap; however, none declares top-level write access, limiting the observed exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/deprecations Version ^1 | — | — |
symfony/polyfill-php86 Version ^1.36 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.