It has frequent releases, a clear README, repository tests, and no install-time scripts. The workflow uses two unpinned actions and the repository lacks a security policy, adding avoidable maintenance and supply-chain hygiene concerns.
68%
Total Score
67
88
75
The repository is owned by an individual rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
All 3 recent commits came from one contributor, leaving maintenance dependent on a single person and increasing abandonment risk if they stop contributing.
The repository has 0 stars and 0 forks, providing little evidence of external adoption or a broader support community. This is supporting evidence only, not a verdict by itself.
Composer build tooling is present, but no security scanning tools were detected, leaving security hygiene less visible.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.0|^8.0 | — | — |
symfony/config Version ^7.0|^8.0 | — | — |
symfony/finder Version ^7.0|^8.0 | — | — |
webmozart/assert Version ^1.0|^2.0 | — | — |
jmf/template-rendering Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.