This release is usable but warrants some caution as a dependency. It is a stable MIT-licensed package with a matching, non-archived repository, a coherent source tree, repository tests, no install-time lifecycle scripts, and a recent release. However, maintenance capacity is thin: only one commit and one active contributor appeared in the last 3 months, all recent commits came from that contributor, and the repository has very low adoption. The absent security policy and undeclared workflow token permissions are transparency and CI-hardening gaps, though the analyzed workflow showed no dangerous patterns. Overall, the package appears maintained and correctly backed, but it has meaningful single-maintainer and low-activity risk.
68%
Total Score
70
100
83
80
Only one registry account has publish access. This is a genuine publishing-resilience concern for a user-owned project, although repository activity shows that the package is still being updated.
The artifact includes a substantial README, while packaged tests and a changelog are absent; the repository compensates for the missing packaged tests with repository tests, but no provided signal covers the missing changelog.
All recent commits came from one contributor, giving a bus factor of one. Because the owner is a user rather than an organization, there is no provided organizational backing to compensate for this concentration.
The repository recorded only 1 commit in the last 3 months from 1 active maintainer. The recent commit confirms activity, but the very low volume indicates a potentially slowing maintenance pace.
The repository has only 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these values provide little evidence of broad community backing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.4|^6.0|^7.0|^8.0 | — | — |
symfony/http-kernel Version ^5.4|^6.0|^7.0|^8.0 | — | — |
symfony/twig-bundle Version ^5.4|^6.0|^7.0|^8.0 | — | — |
symfony/dependency-injection Version ^5.4|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.