The source has no security policy or security scanning, and repository tests are absent. Its MIT licensing, stable version, and recent release history provide useful transparency, but maintenance evidence is limited.
68%
Total Score
75
100
93
75
The repository recorded zero commits and zero active maintainers in the last three months. Although the recent release offsets this somewhat for a data-focused package, the lack of recent development activity limits maintenance confidence.
Composer is used for builds, but no security scanning tools were detected. This is a modest supply-chain hygiene gap rather than evidence that the package is unsafe.
No repository security policy was found, leaving vulnerability reporting expectations undocumented. This lowers transparency but is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.4 | ^6.0 | ^7.0 | ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.