A single contributor made the only commit in the last three months, and all eight workflow actions are unpinned. The package includes tests, release notes, a matching license, and an active organization-owned repository.
67%
Total Score
67
100
88
50
A post-update-cmd lifecycle script runs during Composer updates. This is a supply-chain consideration, but the signal does not show what the script does or that it is unsafe.
The package has 19 releases since 2017, but no registry release in the last two years; this reduces confidence in the freshness of the published artifact despite recent repository activity.
All recent commits came from one contributor, concentrating maintenance responsibility; organization ownership provides some ability to hand off work but does not remove the current concentration.
Only one commit was recorded in the last three months, from one active maintainer, indicating limited recent maintenance momentum even though the repository was recently updated.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.1|^4.0 | — | — |
webmozart/assert Version ^1.10 | — | — |
endroid/installer Version ^1.4 | — | — |
symfony/framework-bundle Version ^6.3|^7.0 | — | — |
symfony/dependency-injection Version ^6.3|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.