The package includes a README and a GitHub release, and its repository is still unarchived. Install-time scripts and no security policy add smaller review concerns.
58%
Total Score
50
88
50
The package runs post-install and post-update Composer scripts, increasing installation-time behavior that should be understood before adoption. No provided signal shows those scripts are unsafe, so this is a review concern rather than a severe risk.
The registry namespace and repository owner match, but the owner is identified as a user rather than an organization. This offers limited backing evidence and does not offset the lack of recent releases.
Only three releases exist, with none in the last 12 months; the latest release was in March 2023, leaving a multi-year maintenance gap. This is the main adoption concern, though the package is not marked deprecated.
Composer is used as the build tool, providing standard dependency management, but no security-scanning tooling is reported. The absence of scanning is a moderate hygiene gap rather than a health verdict.
The linked repository has no security policy, which weakens vulnerability-reporting transparency for a package that handles API tokens and database credentials. This is a modest hygiene gap, not evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.13 | — | — |
symfony/flex Version ^1.19|^2 | — | — |
symfony/yaml Version 5.4.* | — | — |
symfony/dotenv Version 5.4.* | — | — |
symfony/console Version 5.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.