The package is licensed, tested in its repository, documented for consumers, and backed by an organization. Its small user base and limited security process reduce confidence in long-term support.
68%
Total Score
75
88
50
The package has five releases since December 2021, with one release in the last 12 months and a median interval of about 11 months. That indicates a deliberate but slow release cadence rather than abandonment.
The repository recorded no commits and no active maintainers during the last three months. The recent 1.4.0 release provides some compensation, but ongoing maintenance capacity is still uncertain.
The repository uses Make and Composer, but no security scanning tools were detected. This is a modest process gap, not evidence that the package is unsafe.
No security policy was found in the repository, leaving vulnerability-reporting expectations and response procedures unclear.
Both analyzed workflows use unpinned actions, which weakens build reproducibility. The audit found no untrusted checkout, script injection, dangerous trigger, or high-severity finding, so this remains a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
symfony/config Version ^6.4 || ^7.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
nucleos/setlistfm Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.