Tests cover the package, and the repository has clear ownership, licensing, and a current release. The alpha status, sparse release history, no recent commits, and unpinned CI references make this a cautious choice.
68%
Total Score
83
100
78
67
The package has existed for about 3 years and 10 months with six releases, but only one release in the last 12 months indicates a sparse cadence.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful sign of currently limited maintenance capacity.
The repository has no stars or forks and only one watcher. This is weak supporting evidence, though low popularity alone does not make a small package unhealthy.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and verification gap.
The repository has no published security policy, reducing clarity about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
micro/dto Version ^2.0 | — | — |
symfony/finder Version ^6 | — | — |
micro/kernel-app Version ^2.0 | — | — |
micro/plugin-logger-core Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.