Usable with caveats: the package is licensed, documented, stable, organization-backed, and not deprecated or archived. However, it has had zero commits in the last 3 months, only one release in the last 12 months, and lacks a security policy and explicit workflow permissions.
65%
Total Score
75
88
75
The project has existed since May 2022 with 12 releases, but only one release appeared in the last 12 months, indicating a slower maintenance cadence.
There were zero commits and zero active maintainers in the last 3 months, a meaningful warning that current maintenance may have slowed or paused.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-maintenance gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
All six workflows lack top-level permissions declarations. None grants top-level write access, which limits the immediate risk, but explicit least-privilege settings would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tomaj/hermes Version ^4.0 | — | — |
symfony/console Version ^5.4 | ^6.0 | ^7.0 | — | — |
lulco/redis-proxy Version ^1.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.