The package has clear licensing and no install-time scripts, but its source provenance is weak and its release history shows no follow-up activity. The linked repository has no security policy or scanning tools, leaving important maintenance gaps.
0%
Total Score
64
75
This is the only release, published 867 days ago, with no releases in the last 12 months. That strongly suggests abandonment or an unmaintained package.
The repository name does not match the package name, although its README mentions the package. The README reference is compensating evidence, but the mismatch still leaves provenance less clear than a directly matching repository.
The linked repository has 0 stars, 0 forks, and 1 watcher. Popularity is not decisive, but these values reinforce the lack of visible project adoption or community backing.
Composer is used for builds, but no security-scanning tools are present. For a framework with 40 runtime dependencies, this is a meaningful supply-chain hygiene gap.
The repository has no security policy. This is a maintenance and transparency gap for a framework package, with no provided evidence compensating for it.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
brick/math Version ^0.9.3|^0.10.2|^0.11|^0.12 | — | — |
ramsey/uuid Version ^4.7 | — | — |
symfony/uid Version ^6.2 | — | — |
symfony/mime Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.