This release appears generally suitable to depend on: it is a stable MIT-licensed v1.4.0 package, has recent release activity, is not deprecated or archived, and is backed by a matching organization repository with tests and cleanly analyzed workflows. The main reservations are modest current maintenance activity—two commits from one contributor in the last three months—along with no repository security policy, no configured security-scanning tools, and workflow permissions that are not explicitly restricted. The package artifact is also sparse in documentation, although the repository contains a README and tests, which compensates for those artifact-level gaps.
78%
Total Score
80
100
89
80
All two recent commits came from one contributor, producing a 100% top-contributor share. The organization-owned repository provides some handoff capacity, but no second recent contributor is shown, so concentration remains a real risk.
Only two commits were made in the last three months and just one maintainer was active. This shows recent activity but a low maintenance cadence, warranting caution rather than a severe abandonment judgment.
The repository has only 5 stars, 0 forks, and 2 watchers, which suggests limited adoption evidence. Popularity is supporting evidence rather than a decisive health measure, so this is a minor concern.
The repository uses Make and Composer build tooling, but no security-scanning tools are configured. Build reproducibility is supported, while security-process coverage is weaker.
No security policy is present in the repository. This weakens vulnerability-reporting transparency, although it is a process gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.23 | — | — |
p-chess/chess Version ^1.2 | — | — |
symfony/config Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.