Healthy and actively usable, with a few transparency and resilience gaps. It has a long release history, a current non-archived repository, and organization backing, but recent work is concentrated in one contributor and the project lacks a security policy and declared workflow permissions.
78%
Total Score
67
50
88
67
The package has 17 runtime dependencies, including framework, serializer, HTTP, and authentication components. This is a substantial dependency surface to maintain, but it is consistent with the library's API-platform role.
The artifact includes a README, but neither the package nor repository reports tests or a changelog. This reduces transparency for a substantive API library, though the active release history partly compensates.
All 2 recent commits came from one contributor, creating a narrow maintenance base. Organization backing provides some handoff capacity, but no second active contributor is shown.
There were 2 commits in the last 3 months, showing recent activity, but only one active maintainer contributed them. The activity is positive but thin.
The repository uses Composer and has a PHPStan workflow, showing basic build and analysis tooling. No security scanning tool is present, leaving a modest tooling gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.8.0 | — | — |
symfony/finder Version ^5.4 | — | — |
guzzlehttp/psr7 Version ^1.9.1 | — | — |
symfony/routing Version ^5.4 | — | — |
api-platform/core Version 2.6.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.