The license, README, release notes, and pinned workflow actions provide good transparency. Maintenance is concentrated in one contributor, with only one commit in three months and no security policy, so long-term support depends heavily on the publisher.
68%
Total Score
50
100
83
One contributor made all commits during the last three months, giving the project a single-person maintenance dependency. The package is explicitly a personal configuration, which makes this understandable but does not remove the continuity risk.
Only one commit was recorded in the last three months. Although the recent release shows the project is not abandoned, this light activity is a maintenance concern.
The repository has no security policy. For a small configuration package this is not severe, but it reduces transparency about vulnerability reporting and maintenance expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
friendsofphp/php-cs-fixer Version ^3.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.