A clear README, release notes, MIT license, and matching repository improve transparency. It has one focused dependency and no install-time scripts, but the project’s very small footprint limits confidence.
58%
Total Score
50
100
81
75
There were no commits or active maintainers in the last three months, consistent with more than four years since the last push and a meaningful abandonment concern.
The package has only three releases, with none in the last four years; the long median release interval indicates materially slowed maintenance.
The repository has zero stars and only one fork and watcher, offering little evidence of a broad user or contributor base. This supports the maintenance concern but is not decisive alone.
Composer is used for the build, but no security-scanning tools are present, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/filesystem Version ^3|^4|^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.