Clear documentation, tests, a changelog, and a security policy improve confidence. Organizational backing helps, but limited adoption and no automated security scanning leave less independent assurance.
62%
Total Score
83
50
88
75
The release declares 59 runtime dependencies, including framework, storage, search, authentication, and media components. That broad dependency surface increases upgrade and transitive-maintenance burden.
post-install-cmd and post-update-cmd scripts run during dependency operations. They may be normal Composer behavior, but they increase installation complexity and warrant checking before use.
The package is only 110 days old, with 10 releases concentrated in 14 days and a median interval of about 2 hours 21 minutes. This shows activity but provides little evidence of long-term stability.
One contributor made all 105 commits in the last 3 months. Organization ownership provides some handoff capacity, but there is still no observed second active contributor.
Composer build tooling is present, but no security-scanning tools were detected. The missing automated scanning reduces assurance for a package with many runtime dependencies.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12|^3.0 | — | — |
symfony/uid Version 8.0.* | — | — |
doctrine/orm Version ^3.6 | — | — |
lcobucci/jwt Version 5.5 | — | — |
symfony/flex Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.