The repository has basic build and test scaffolding, but its documentation is still a template and it has no security policy. Install scripts and unpinned workflow actions add maintenance and supply-chain hygiene concerns.
35%
Total Score
0
58
50
The latest release was in August 2020, with no releases in the preceding 12 months of collection and only seven releases overall. This is strong evidence that the package is no longer actively maintained.
There were zero commits and zero active maintainers in the measured three-month period. Combined with the old release history, this indicates sharply reduced maintenance capacity.
The manifest declares the package proprietary, with no recognized license and no license file in the package or repository. That leaves consumers without clear open-source reuse terms.
The package runs post-install and post-update Composer scripts, increasing the amount of package code executed during dependency operations. No provided signal shows those scripts are unsafe, so this is a hygiene concern rather than a severe finding.
A README is present and the repository reports tests, but the README remains a generic project template and provides limited consumer guidance. The absence of tests or a changelog in the published artifact is normal packaging practice.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version 5.1.* | — | — |
symfony/dotenv Version 5.1.* | — | — |
symfony/console Version 5.1.* | — | — |
symfony/twig-bundle Version 5.1.* | — | — |
symfony/monolog-bundle Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.