Clear documentation, tests, licensing, and a security policy make integration and support expectations easy to assess. The project is still early-stage, so future compatibility and continuity depend heavily on its sole maintainer.
72%
Total Score
50
100
81
100
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
Seven releases in 41 days, with a median interval of about 1 day, shows active development but also reflects a very young project whose release pattern has not yet stabilized.
One contributor made all 55 recent commits, giving the project a single-person bus factor. The concentrated ownership is a real continuity risk for a young beta package.
The repository recorded 55 commits in the last three months, showing strong recent activity. However, that activity is concentrated in one contributor, limiting resilience if the maintainer becomes unavailable.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.4 | — | — |
symfony/process Version ^5.4|^6.0|^7.0|^8.0 | — | — |
nikic/php-parser Version ^4.19|^5.0 | — | — |
symfony/filesystem Version ^5.4|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.