The package includes clear licensing, documentation, and a changelog, while Composer and Dependabot provide basic project hygiene. Its beta status, single active contributor, and unpinned workflow actions leave more maintenance and build-reproducibility risk than a mature release.
78%
Total Score
83
94
67
All 46 recent commits came from one contributor, leaving maintenance dependent on a single active individual. Organization backing provides some handoff capacity, but no second active contributor is shown.
The repository has no published security policy, which reduces transparency about vulnerability reporting and response.
Version 4.1.0-beta1 is a prerelease, so compatibility may still change even though prereleases represent only 5% of recent releases.
The sole workflow was fully analyzed with no reported audit findings or untrusted execution paths. However, all 6 action references are unpinned, leaving avoidable build reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
doctrine/dbal Version ^3.10 || ^4.0 | — | — |
symfony/asset Version ^6.4 || ^7.4 | — | — |
symfony/config Version ^6.4 || ^7.4 | — | — |
symfony/string Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.