The package is tightly scoped, has only two runtime dependencies, and is neither deprecated nor archived. Organization ownership helps, but limited documentation and the absent security policy reduce confidence.
42%
Total Score
100
100
63
75
Only one release exists, published nearly nine years ago, with no releases in the last 12 months. That is strong evidence of an abandoned or unfinished package.
The artifact contains no README, tests, or changelog. For this very small four-file policy package, missing tests and changelog are expected packaging gaps, but the absent README modestly reduces consumer guidance.
Composer is used for the build, but no repository security-scanning tools are present. This is a modest transparency and maintenance gap rather than a standalone adoption blocker.
The repository is not archived, but its last push was over seven years ago; the non-archived status does not offset the stale activity by itself.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.2 | — | — |
drutiny/drutiny Version 2.x-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.