This is a generally usable and well-documented package with a stable release, frequent registry releases, an MIT license, tests, substantial source structure, safe read-only workflow permissions, and no deprecation or archive status. The main concerns are that repository commit activity shows no commits and no active maintainers in the last 3 months, the package has only one registry maintainer, and the repository lacks a security policy and security-scanning tooling. The recent release and push timestamps provide some evidence of ongoing publishing, but the apparent lack of recent commit activity limits confidence in sustained maintenance; adoption is reasonable with routine dependency and release monitoring.
72%
Total Score
50
100
89
90
Only one registry account has publish access, which creates a limited publishing bus factor. Because the repository is user-owned rather than organization-backed, there is no organizational ownership evidence to compensate for this limitation.
The repository is owned by the user account manuxi, not an organization. This is consistent with a small personal project but provides less institutional backing or maintainer redundancy.
The repository records 0 commits and 0 active maintainers over the last 3 months. This conflicts somewhat with the frequent release history and recent push timestamp, but the observed activity still warrants caution about sustained development capacity.
The repository has 1 star, 1 fork, and 1 watcher, so external adoption and community redundancy appear limited. Popularity is supporting evidence only, and the package otherwise has meaningful documentation and structure.
Composer is used as a build tool, but no security-scanning tools are detected. The absence of scanning lowers security-process transparency, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version ^3.0 | — | — |
symfony/intl Version ^6.4 | ^7.0 | — | — |
symfony/config Version ^6.4 | ^7.0 | — | — |
twig/intl-extra Version ^3.23 | — | — |
twig/extra-bundle Version ^3.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.