The MIT license, tests, release notes, and a matching source repository provide useful transparency. The small maintainer base and absent security policy leave less support if maintenance slows further.
62%
Total Score
50
93
75
Only one registry account has publishing access. The repository is user-owned rather than organization-backed, so there is no shown maintainer depth to offset that concentration.
The registry namespace and repository owner match, but the owner is an individual rather than an organization, providing limited visible project backing.
The package has only four releases since May 2020 and none in the last 12 months; the roughly 23-month median interval indicates a slow maintenance cadence.
There were zero commits and zero active maintainers in the last three months, reinforcing the concern raised by the long release gap.
The repository has no security policy, leaving no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^5.0 || ^6.0 | — | — |
beberlei/assert Version ^3.3.2 | — | — |
symfony/http-foundation Version ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.