This is a healthy, actively developed release with strong recent maintenance evidence: 11 releases in 72 days, 218 commits in the last 3 months, recent repository activity, extensive source documentation, repository tests, security scanning, and a security policy. The main concerns are that nearly all recent commits come from one contributor, the package uses a post-install lifecycle script, and GitHub Actions workflows do not declare top-level permissions; these warrant review but do not outweigh the package’s active development and repository hygiene. Its young age and low popularity limit maturity evidence, so dependency adoption should still include normal upgrade and maintainer-continuity monitoring.
80%
Total Score
70
100
94
80
A post-install-cmd script introduces install-time behavior that consumers should inspect, although the signal does not establish that the script is unsafe or unusually complex.
Only one registry account has publish access. Because the repository is user-owned rather than organization-owned, this represents some publishing continuity risk, although repository activity shows an active maintainer.
The linked repository is owned by an individual user, not an organization, so there is no organizational backing to compensate for the concentrated contributor and single registry publisher base.
Two contributors were active, but the top contributor made 217 of 218 commits, creating a highly concentrated maintenance dependency. The second contributor’s activity is too small to materially offset that concentration for a user-owned project.
The repository has only 6 stars, 1 fork, and 0 watchers. This is limited supporting evidence of community adoption, but popularity is not decisive for a small, actively maintained package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1 || ^2.0 | — | — |
typo3/cms-core Version ^13.4 || ^14.0 | — | — |
symfony/console Version ^7.0 || ^8.0 | — | — |
symfony/routing Version ^7.0 || ^8.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.