Clear documentation, release notes, licensing, and static analysis support adoption. Unpinned workflow actions and the very concentrated contributor base leave more maintenance and build-integrity risk than a mature project.
68%
Total Score
83
79
50
The artifact includes license files and declares LGPL-3.0-or-later, which is positive, but detected GPL-3.0 text is not fully covered by that declaration and warrants clarification.
The package is only 44 days old with three releases, so its maintenance record is still too short to establish long-term stability.
All 28 recent commits came from one contributor, creating a concentrated maintenance dependency even though the repository is owned by an organization.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Version v0.2.1 is below 1.0, indicating an early API and compatibility stage, although it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.10 | — | — |
symfony/form Version ^7.4 | — | — |
symfony/mime Version ^7.4 | — | — |
symfony/config Version ^7.4 | — | — |
symfony/routing Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.