The package is clearly licensed and documented, backed by an organization, and has no install-time scripts. Its small footprint leaves limited evidence about testing and security practices.
61%
Total Score
75
86
75
Only two releases were published, both in January 2026, with no later release over roughly eight months. That is a meaningful maintenance concern for a package still at its first stable major version.
The repository recorded zero commits and zero active maintainers in the three months before collection, suggesting maintenance has paused. The package is young, so this is caution rather than evidence of abandonment on its own.
Composer is used for the build, but no security-scanning tooling was detected. The absence limits evidence of proactive security hygiene without showing that the release is unsafe.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported. This is a minor concern for a small package, not a severe dependency risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimcore/pimcore Version ^11.0 | — | — |
symfony/http-foundation Version ^6.4 | — | — |
mhujer/breadcrumbs-bundle Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.