The package includes a substantial README, tests, and a repository that matches its name. Its release history is only hours old, with no observed three-month commit activity, and it declares a proprietary license without a license file; security scanning is also absent.
62%
Total Score
50
71
75
The manifest declares a proprietary license, with no detected license text and no license file in the package or repository. This leaves adoption and redistribution rights unclear for an open-source dependency.
The source repository is owned by an individual account rather than an organization, so the short observed maintenance history has no organizational backing to offset it.
The package is less than one day old despite having five releases, so its maintenance record and production maturity are not yet established.
The repository shows zero commits and zero active maintainers in the last three months. Because the package is newly published, this is partly explained by its age, but it still provides no evidence of an established maintenance cadence.
Composer is used for the build, but no security scanning tools are present. This is a transparency and hygiene gap rather than evidence that the release is unsafe on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/routing Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/validator Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/serializer Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.