Usable with caveats: the release is clearly packaged, licensed, documented, and backed by an active non-archived repository. It is still very young, with only four recent commits from one contributor and no security scanning, so long-term maintenance capacity is unproven.
68%
Total Score
50
81
100
The repository is owned by a user account rather than an organization, so the concentrated maintainer activity is not offset by visible organizational backing.
The package is only 44 days old with three releases and a median interval of about 4 days, showing active initial development but limited track record.
All four recent commits came from one contributor, creating a meaningful dependency on a single maintainer with no demonstrated handoff capacity.
Four commits were made in the last three months, which supports current activity but is a small maintenance record for a new package.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.6 || ^4.0 | — | — |
meyfa/php-svg Version ^0.16.1 | — | — |
contao/core-bundle Version ^5.3 || ^5.4 || ^5.5 || ^5.6 || ^5.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.