The project is only about five months old and has no commits in the last three months. Its small scope, tests, clear README, MIT licensing, and clean workflow audit offset some risk, but all three workflow actions are unpinned and no security policy is present.
68%
Total Score
50
100
83
67
The package is about five months old and has only two releases, both published within about one hour, so its long-term maintenance record is still unproven.
The repository recorded no commits and no active maintainers in the last three months, a meaningful sign that maintenance may have stalled.
The repository has zero stars, forks, and watchers. This is weak supporting evidence rather than a verdict, but it provides no external adoption signal for this young project.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.