Documentation, tests, release notes, and licensing are all in place. Maintenance has gone quiet for about one year, with no recent commits or issue activity, and the repository lacks a security policy.
62%
Total Score
50
100
94
75
The package has 37 releases since June 2020, but none in the last 12 months; its latest release was about one year ago. This indicates slowed maintenance despite a substantial release history.
There were no commits and no active maintainers in the last three months. Combined with no releases in about one year, this is meaningful evidence of reduced maintenance capacity.
There were no new or closed issues or pull requests in the last month, with one pull request still open. This supports the picture of limited current activity.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
All workflows were analyzed with no untrusted checkouts or script injection, and the only finding was a low-confidence cache-poisoning pattern. The workflow also leaves action references unpinned, which is a minor reproducibility concern rather than a severe risk here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/serializer Version ^6.4 || ^7.0 | — | — |
symfony/property-access Version ^6.4 || ^7.0 | — | — |
php-http/message-factory Version ^1.1 | — | — |
symfony/event-dispatcher Version ^6.4 || ^7.0 | — | — |
phpdocumentor/reflection-docblock Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.