Tests, documentation, and organization backing provide useful safeguards. The early 0.3.0 status, missing security policy, and weak workflow pinning leave maintenance and release hygiene less mature.
55%
Total Score
50
79
50
The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating no recent development activity and raising maintenance risk.
The package has only 3 releases, all within its first year, with the latest release roughly 10 months ago; this shows an early project with no recent release evidence.
Composer build tooling is present, but no security scanning tooling was detected, leaving automated security coverage limited.
The repository has no security policy, leaving the project's process for receiving and handling vulnerability reports unclear.
Version 0.3.0 is not a stable major release, so APIs may still change; it is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
p8p/client Version self.version | — | — |
symfony/finder Version ^7.3 | — | — |
symfony/console Version ^7.3 | — | — |
cebe/php-openapi Version ^1.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.