Usable with caveats: it is a young, well-structured extension with tests, a README, regular releases, and an active repository, but maintenance currently depends on one contributor and the project has limited security documentation.
68%
Total Score
50
100
81
90
The registry namespace and repository owner match, but the owner is an individual rather than an organization, so there is no demonstrated organizational backing beyond the maintainer.
The package is only 43 days old but has 13 releases, with a median interval of about 4 days; this shows active iteration, while its short history limits evidence of long-term reliability.
All recent commits came from one contributor, so maintenance could be disrupted if that contributor becomes unavailable; the repository is user-owned rather than organization-owned, offering no shown organizational handoff capacity.
Only one commit was recorded in the last three months, with one active maintainer; this is a meaningful maintenance concern, although the recent release cadence shows ongoing registry activity.
The repository name matches the package name, which supports package ownership, but its README does not mention the package; this is a transparency gap under the package-mention check.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/yaml Version ^7.3|^8.0 | — | — |
helgesverre/toon Version ^3.1 | — | — |
symfony/filesystem Version ^7.3|^8.0 | — | — |
ineersa/hatfield-extension-api Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.