The package includes tests, a README, and a matching MIT license, while its organization-backed repository is not archived. Recent registry releases are healthy, but no commits were recorded in the last three months and the repository has no security policy.
67%
Total Score
75
100
89
75
The repository recorded zero commits and zero active maintainers during the last three months. This is concerning for maintenance capacity, although the registry shows a release during that period.
The repository name does not match the registry package name and its README does not mention the package. The package README identifies it as a subtree split, which partly explains the mismatch, but ownership remains less directly verifiable.
Composer build tooling is present, but no security-scanning tool was detected. That leaves a modest transparency gap for a maintained dependency.
The repository has no security policy, so users have no documented reporting or response process for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
simshaun/recurr Version ^2.2 | — | — |
enhavo/app-bundle Version ^0.15 | — | — |
enhavo/form-bundle Version ^0.15 | — | — |
enhavo/block-bundle Version ^0.15 | — | — |
symfony/http-client Version ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.