The small interface-only source tree and clean Composer dependency profile limit complexity. However, maintenance evidence is thin, with no commits in three months, no tests or README, and a repository naming mismatch that weakens transparency.
58%
Total Score
33
100
67
88
There were zero commits and zero active maintainers in the last three months, which is meaningful abandonment risk for a package with only one release.
No README, tests, or changelog are present, but this is a very small interface-only package and missing tests or changelog are normal packaging practice. The absent README is a minor consumer-documentation gap.
The package and repository are tied to a user-owned account rather than an organization, so the single registry maintainer provides limited visible continuity.
The package has only one release, published 215 days ago, so there is little evidence of an established release cadence or continued maintenance.
There are no open issues or pull requests and no recent issue or pull-request activity; for a tiny package this is not inherently negative, but it offers no evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-kernel Version ^8.0 | — | — |
symfony/event-dispatcher Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.