The project is young but releases frequently, with a clear README, tests, MIT licensing, and a security policy. Its broad runtime dependency set and lack of security scanning add maintenance exposure.
67%
Total Score
83
50
89
100
The release declares 29 runtime dependencies, including framework, authentication, persistence, and messaging components. This breadth increases upgrade and compatibility exposure for consumers.
One contributor made all 53 commits in the last three months, giving the project a complete single-person concentration. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has zero stars, forks, and watchers. Because the package is only 103 days old, this is weak supporting evidence rather than a standalone abandonment signal.
Composer is used for builds, which is appropriate for a Packagist package. No security-scanning tooling was detected, leaving a meaningful quality and supply-chain check uncovered.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/cache Version ^3.0 | — | — |
symfony/uid Version ^7.4 || ^8.0 | — | — |
doctrine/orm Version ^3.0 | — | — |
symfony/mime Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.