Its documentation, tests, licensing, and organization backing are solid. Workflow action pinning is weak, and the source does not explicitly mention this package.
42%
Total Score
67
100
72
75
The latest registry release was published in March 2021, with no releases in the following five years. That long gap is strong evidence of abandonment risk despite the package having a substantial release history.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the multi-year release gap. This materially increases abandonment risk.
The repository name does not match this package and its README does not mention it. The repository tree and description indicate a multi-library monorepo, which makes the mismatch understandable but still leaves package ownership less explicit.
The repository has zero stars and watchers and one fork, offering little supporting evidence of broad community use. Popularity is only supporting evidence, so this is a minor concern rather than a primary verdict.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a hygiene gap, not evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/uri Version ^6.0 | — | — |
symfony/yaml Version ~4.4.9 || ^5.0 | — | — |
symfony/string Version ^5.0 | — | — |
psr/http-client Version ^1.0 | — | — |
symfony/console Version ^4.4 || ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.