Documentation and packaging are in good shape, with an MIT license, tests, and regular releases. Maintenance resilience is limited by zero commits in the last three months and a single registry maintainer; the repository also has no security tooling.
64%
Total Score
50
100
89
50
Only one registry maintainer is listed, limiting publishing redundancy and increasing continuity risk despite the package's release activity.
The package and repository are tied to the same individual owner rather than an organization, so the single-maintainer concern is not offset by organizational backing.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of current maintenance despite recent registry releases.
The repository has zero stars and forks and only one watcher, indicating little visible adoption. This is supporting evidence only and does not outweigh the release and licensing signals.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.2 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.