The repository includes a substantial test suite, a changelog, a matching README, and active recent commits. Its short history, highly concentrated contribution pattern, absent security policy, and entirely unpinned workflow actions leave meaningful maintenance and build-reproducibility concerns.
68%
Total Score
67
100
88
83
The repository is owned by an individual user rather than an organization, so the highly concentrated contribution pattern has no shown organizational handoff support.
The package is nearly two months old and has three releases, all within a very short period. This shows early activity but provides little long-term maintenance history.
Two contributors were active, but one contributor made 19 of 20 recent commits, leaving maintenance heavily dependent on a single person.
The project uses Composer and Task for builds, but no security-scanning tools were detected. That is a meaningful security-process gap for a dependency intended to run in development environments.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.10 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
mongodb/mongodb Version ^2.0 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
symfony/routing Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.