Maintenance depends on one contributor, and the repository has no security policy while all four workflow actions are unpinned. The README, repository tests, recent releases, and lack of deprecation provide useful reassurance.
66%
Total Score
50
100
75
Only one account has registry publishing access. This is a modest publishing and continuity concern for a user-owned project, although registry access does not by itself measure actual development activity.
The repository is owned by an individual rather than an organization, so the single-contributor and single-maintainer concentration represents a genuine continuity concern.
One contributor made all commits in the last three months, so maintenance knowledge and release capacity are concentrated in a single person.
Only one commit was recorded in the last three months, indicating limited recent development activity even though the package was released during that period.
The repository has no security policy. That weakens the project's documented process for receiving and handling vulnerability reports.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/asset Version ^6.4 || ^7.0 | — | — |
symfony/config Version ^6.4 || ^7.0 | — | — |
contao/core-bundle Version ^5.3 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 | — | — |
league/oauth2-client Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.