The repository remains active under organization ownership, and the package has a clear README with no install-time scripts. A single recent contributor, no security policy, and an incomplete workflow audit leave maintenance and release controls thin.
55%
Total Score
67
83
67
The manifest declares a proprietary license, with no detected license text or license file. This creates a real adoption and redistribution constraint for an open-source dependency.
The package has 20 releases, but the latest was over four years ago and there were no releases in the last 12 months. Recent repository activity partly offsets the age of the published release.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository recorded one commit in the last three months from one active maintainer, showing some current activity but not a strong maintenance cadence.
The repository has no security policy, leaving reporting and response expectations undocumented for a deployment-oriented tool.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version >4.0 | — | — |
symfony/dotenv Version >4.0 | — | — |
symfony/console Version >4.0 | — | — |
symfony/process Version >4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.