The package includes a clear README, tests, a matching source tree, and an MIT license. Low community activity and the absence of a security policy leave support and security response dependent on one maintainer.
78%
Total Score
70
100
89
83
Only one registry account has publish access. This is a resilience caution because a single publisher can delay releases or corrective maintenance.
The repository is owned by an individual user rather than an organization, so there is no visible organizational maintenance backing to offset the concentrated contributor base.
All 4 recent commits came from one contributor, creating a concentrated maintenance risk in this user-owned project.
The repository has 0 stars and 0 forks, so it has little visible community adoption. Popularity is supporting evidence rather than a health verdict, but this reduces external validation.
Composer build tooling is present, but no security scanning tools were detected, leaving fewer automated checks for dependency or code risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.3 | — | — |
psr/http-message Version ^1.0 | — | — |
phpunit/php-code-coverage Version ^9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.