Usable with caveats: the release is licensed, documented, tested, and backed by an active-looking repository with sensible build and security tooling. However, the registry shows no release in about 18 months and the repository recorded no commits in the last three months, so verify ongoing compatibility before adopting it.
72%
Total Score
50
93
88
The package has six releases since September 2023, but none in about 18 months despite the repository being updated more recently. This weakens confidence in release maintenance and compatibility coverage.
No commits or active maintainers were recorded in the last three months. This is a meaningful maintenance concern, although the non-archived repository and recent push provide some counterevidence.
All four workflows lack top-level token permissions and none declares read-only permissions. Although no workflow requests top-level write access, explicitly constraining permissions would improve CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5|^6|^7 | — | — |
doctrine/dbal Version ^2.9|^3|^4 | — | — |
illuminate/bus Version >=5.7 | — | — |
illuminate/http Version >=5.7 | — | — |
horstoeko/zugferd Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.