Tests, a README, and an organization-backed repository provide useful support. The missing security controls and fully unpinned workflow actions leave important maintenance gaps.
61%
Total Score
83
75
50
The package was released today and has only one registry release, so there is no track record yet for maintenance or release stability.
All eight recent commits came from one contributor, leaving maintenance dependent on a single active developer. Organization backing provides some handoff capacity but does not remove the concentration risk.
The project uses Make and Composer for builds, but no security-scanning tooling was detected, reducing transparency around automated security checks.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
Version v0.1.0 is an early, non-stable-major release, which signals a less mature API and a higher likelihood of breaking changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/uid Version ^7.3|^8.0 | — | — |
symfony/yaml Version ^7.3|^8.0 | — | — |
symfony/config Version ^7.3|^8.0 | — | — |
symfony/console Version ^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.