Usable with caveats: the package is licensed, documented, tested, actively released, and backed by a matching repository. However, the repository had no commits or active maintainers in the last three months, has almost no adoption, and lacks security policy and scanning.
68%
Total Score
50
100
89
88
The package and repository are owned by the same individual account, providing direct ownership alignment, though there is no organization backing to broaden maintenance capacity.
There were 0 commits and 0 active maintainers during the last 3 months, which is the main maintenance concern despite the recent release and non-archived repository.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently unhealthy, but it provides little evidence of an active user or maintainer feedback loop.
The repository has only 1 star, 0 forks, and 0 watchers. Popularity is supporting evidence rather than decisive, but these figures provide little evidence of broad community validation.
Composer build tooling is present, but no security-scanning tools are reported. The missing scanning reduces supply-chain transparency, though it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.4 || ^6.0 || ^7.0 | — | — |
symfony/console Version ^5.4 || ^6.0 || ^7.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.