The organization-owned repository matches the package’s documented purpose, and the README provides concrete installation and configuration guidance. Its small dependency surface and lack of install-time scripts reduce adoption risk, but ongoing maintenance remains uncertain.
58%
Total Score
50
100
88
83
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the absence of recent releases and raising maintenance risk.
The package is about 16 months old with only 3 releases, and it has had no releases in the last 12 months. This indicates a very limited and currently inactive release cadence.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe to depend on.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, although it does not by itself indicate abandonment.
No GitHub Actions workflows were present, so there were no workflow permissions, trigger, or action-pinning risks to assess. This also provides no evidence of automated maintenance or security checks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1|^2|^3 | — | — |
symfony/cache Version ^6.0 | — | — |
symfony/console Version ^6.0 | — | — |
symfony/http-kernel Version ^6.0 | — | — |
symfony/serializer-pack Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.