This is a young but actively maintained Composer package: it has 15 releases in 92 days, recent repository activity, a clear MIT license, a substantial README, a matching source repository, and no deprecation or install-time lifecycle scripts. Adoption carries moderate maintenance risk because all 26 recent commits come from one contributor, the artifact and repository contain no tests or changelog, the repository has no security policy or security scanning, and the package remains on an unstable 0.x major version. Overall it appears usable for dependency adoption, but consumers should expect a relatively immature project and consider pinning versions and monitoring maintenance.
72%
Total Score
75
100
78
90
A substantial README documents installation and usage, but neither the artifact nor repository contains tests or a changelog, leaving useful maintenance and regression-safety gaps for a young package.
The linked repository is owned by an individual user, not an organization, so the concentrated maintainer activity cannot be discounted as normal organization-level ownership.
One contributor made all 26 commits in the last three months, creating a significant single-maintainer continuity risk; the repository owner is an individual user rather than an organization.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but it is not by itself a decisive health problem for a young, specialized package.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning reduces assurance but is not severe on its own for this package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/framework-bundle Version ^6.1|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.