Healthy and reasonable to depend on, with strong project hygiene and a recent stable release. The main caveat is that repository activity has been quiet for the last three months and the project lacks security-specific safeguards.
78%
Total Score
67
100
94
67
No commits and no active maintainers were observed during the last three months, which raises a maintenance responsiveness concern despite the recent release.
The repository has 18 open issues and 14 open pull requests, with no new or closed issues or merged pull requests in the last month, suggesting limited recent attention.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and assurance gap.
The repository has no SECURITY.md or other detected security policy, making vulnerability reporting less clear for users.
The only workflow does not declare top-level token permissions, so its GitHub Actions permissions are less explicit than recommended; it does not declare top-level write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.