The package includes tests, release notes, a license, and a small dependency set, with no install-time scripts. Maintenance is concentrated in one contributor, and the workflow uses both actions without pinning; the missing security policy is a smaller transparency gap.
76%
Total Score
60
100
94
75
Only one account has registry publish access. Because the repository is owned by an individual rather than an organization, this represents a real continuity risk despite active repository work.
The registry namespace and repository are owned by the same individual, so the package has clear ownership but no organizational backing shown by the collected evidence.
One contributor made all recorded commits in the last three months, with a 100% share. For this individually owned project, that concentration creates a meaningful continuity risk.
There is one open issue and one open pull request, with no issues or pull requests opened or closed in the last month. This is a mild indication of limited community activity, not abandonment by itself.
The repository reports zero stars, forks, and watchers. This is weak supporting evidence and lowers confidence in community resilience, but it does not outweigh the observed maintenance activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.0 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/console Version ^5.0 || ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.