A clear README, tests, MIT licensing, and a recent stable release support adoption. The small maintainer base, absent security policy, and lightly active repository leave less resilience for future maintenance. Installation also runs a post-autoload-dump script, so inspect that behavior before deploying.
68%
Total Score
50
100
93
50
A post-autoload-dump install-time script runs during dependency setup, adding execution behavior that should be understood before use.
The project has existed since July 2018 with 75 releases, but only one release in the last 12 months indicates a slower current cadence.
All recent repository activity comes from one contributor, leaving maintenance dependent on a single individual.
Only one commit was recorded in the last three months, showing limited recent development activity despite the recent release.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^8 | — | — |
symfony/config Version ^8 | — | — |
symfony/finder Version ^8 | — | — |
symfony/console Version ^8 | — | — |
nette/php-generator Version ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.