The package includes tests, a useful README, and read-only workflow permissions. Its declared GPL-3.0-or-later conflicts with the detected LGPL-3.0 license, while all nine workflow actions are unpinned and installation runs lifecycle scripts.
55%
Total Score
100
58
50
This is the package's only release, published about 2 years and 8 months ago, with no releases in the last 12 months. That leaves maintenance and compatibility uncertain.
A license file is present, but it identifies LGPL-3.0 while the manifest declares GPL-3.0-or-later. The mismatch should be clarified before adoption.
The package runs post-install and post-update Composer scripts, adding installation-time behavior that deserves review beyond ordinary dependency loading.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counters provide little external evidence of adoption or review.
Composer and Make tooling are present, showing a reproducible development workflow. No security-scanning tools are configured, leaving a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.3|^7.0 | — | — |
symfony/runtime Version ^6.3|^7.0 | — | — |
symfony/twig-bundle Version ^6.3|^7.0 | — | — |
symfony/framework-bundle Version ^6.3|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.