The latest release includes concrete fixes and the repository is active enough to publish a current stable version. No recent commits, no security policy, and a license-file mismatch leave maintenance and licensing questions to resolve.
68%
Total Score
75
100
88
75
The package declares LGPL-3.0-or-later and includes a license file, but the detected artifact license is GPL-3.0, so the licensing terms do not align cleanly.
There were zero commits and zero active maintainers in the last three months, a meaningful sign of currently limited development activity even though a release was published during the period.
The repository uses Composer, appropriate for this PHP package, but no security-scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/routing Version ^5.4 || ^6.4 || ^7.0 | — | — |
contao/core-bundle Version ^4.13 || ^5.0 | — | — |
symfony/http-kernel Version ^5.4 || ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.