The project includes tests, changelog, release notes, and a clear MIT license, which support dependable adoption. Repository activity has paused recently, while all four workflow actions are unpinned and no security scanning is configured.
68%
Total Score
75
50
94
83
The package has 20 runtime dependencies, including broad Symfony, Twig, and geocoder integration components; this is a substantial dependency surface that can increase upgrade and compatibility burden.
The repository recorded 0 commits and 0 active maintainers over the last 3 months, a meaningful sign of recently quiet maintenance despite the recent release and push timestamp.
There are 4 open issues and 13 open pull requests, while none were opened or merged in the last month; the backlog and lack of recent issue or PR movement suggest slower project responsiveness.
The project uses Make and Composer for builds, but no security-scanning tools were detected, leaving a security-hygiene gap in the repository.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
twig/twig Version ^2.4 || ^3.0 | — | — |
symfony/form Version ^7.4 || ^8.0 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
symfony/http-client Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.