The MIT license, included tests, organization-backed repository, and steady release history support adoption. Recent commit silence, absent security policy, and unpinned workflow actions leave maintenance and build-integrity concerns.
70%
Total Score
75
50
94
75
Twenty-seven runtime dependencies is a substantial dependency surface for a core library, adding maintenance exposure, but the profile is consistent with its broad framework functionality.
No commits and no active maintainers were observed during the last three months. The recent repository push and active release history partly offset this, but the gap still raises maintenance-continuity concern.
Composer build tooling is present, but no security-scanning tooling was detected, leaving fewer automated checks for dependency or code risks.
The repository has no published security policy, reducing transparency about vulnerability reporting and response expectations.
The workflow audit completed successfully and found read-only permissions with no untrusted checkout or injection findings. However, both analyzed action references are unpinned, weakening build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.20 | — | — |
ramsey/uuid Version ^4.1 | — | — |
doctrine/orm Version ^3.0 | — | — |
enjoys/config Version ^1.0 | — | — |
enjoys/cookie Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.