Healthy and suitable to depend on. It has frequent releases, active work from nine maintainers, tests, documentation, security policy, and organization backing; the main caveats are install-time scripts and a relatively large dependency surface.
88%
Total Score
100
50
94
70
One of 21 workflows uses pull_request_target, which warrants review because that trigger can increase CI exposure. No untrusted checkouts or script-injection patterns were detected, keeping this from being a severe concern.
The release declares 40 runtime dependencies and 37 development dependencies, creating a relatively broad integration and update surface for consumers. This is a real complexity caveat, but the active project and extensive tooling provide some compensation.
The package uses post-install, post-update, and pre-autoload-dump scripts. These add install-time behavior that should be reviewed before adoption, although their presence alone does not show that the release is unsafe or unmaintained.
Twelve workflows declare read-only permissions, but eight omit top-level permissions and one declares top-level write access. This is a CI hardening gap, though it is partly offset by the otherwise documented permission configuration.
Version 0.44.1 is not a stable-major release, so compatibility guarantees may be weaker than for a 1.x package. It is not a prerelease and recent releases show an established development cadence, partly offsetting that concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
brick/math Version ^0.12 || ^0.13 || ^0.14 || ^0.15 || ^0.16 || ^0.17 || ^0.18 | — | — |
cmsig/seal Version ^0.12 | — | — |
symfony/uid Version ^6.4 || ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.