The project has organization backing, a matching repository, a useful README, tests in the source project, and a documented release. Its small release history and limited security tooling leave less assurance than a mature dependency, while the workflow references need pinning.
68%
Total Score
75
100
88
83
The repository recorded zero commits and zero active maintainers in the last three months. Although a recent release provides some compensation, the current absence of development activity raises maintenance risk.
Only two issues are open, with no new or closed issues and no pull requests in the last month. This is quiet rather than clearly unhealthy, but it provides little evidence of active community maintenance.
The project uses Make and Composer build tooling, but no security-scanning tools are detected. The missing scanning is a hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. For a file-management bundle handling uploads and downloads, this weakens vulnerability-reporting transparency.
Version 0.1.7 is not a prerelease, but the package remains below 1.0, so its API and behavior may still change more substantially than a stable-major dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0.4 | — | — |
symfony/mime Version ^6.4|^7.0|^8.0 | — | — |
symfony/routing Version ^6.4|^7.0|^8.0 | — | — |
symfony/http-kernel Version ^6.4|^7.0|^8.0 | — | — |
symfony/http-foundation Version ^6.4|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.