Clear documentation, release notes, and recent repository work reduce adoption uncertainty. Keep deployment controls tight because the package runs Composer lifecycle commands and bundles many runtime dependencies.
67%
Total Score
67
50
88
50
Thirty-eight runtime dependencies make the package relatively complex to update and audit, including a broad Symfony surface and several embedded web components. The profile is manageable but increases maintenance exposure.
The package declares LGPL-2.1-or-later and includes license files, but the artifact also contains MIT and BSD-3-Clause licensed components not covered by that declaration. This is licensed, though the bundled-license picture needs careful review.
The package runs post-install and post-update Composer commands, which expands the trust placed in installation and update operations. This is a supply-chain hygiene concern even though it is not evidence of malicious behavior.
The repository is owned by a personal GitHub account rather than an organization, so there is no provided evidence of organizational handoff capacity. This makes the concentrated commit pattern more significant.
One contributor made 47 of 52 recent commits, or about 90%, despite three contributors being active. That concentration creates a meaningful continuity risk for a user-owned repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version >=6.4 | — | — |
symfony/intl Version >=6.4 | — | — |
symfony/mime Version >=6.4 | — | — |
symfony/yaml Version >=6.4 | — | — |
cocur/slugify Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.