The project has a clear README, repository tests, and an MIT license. Its workflow is audited, though it lacks security tooling and pins none of its four referenced tools or actions.
61%
Total Score
67
93
50
This release was published today and is the package's only release, so there is no demonstrated maintenance or compatibility history yet.
All eight recent commits came from one contributor, leaving maintenance dependent on a single active developer. Organization ownership provides some handoff capacity but does not remove the concentration risk.
The repository has eight commits in the last three months, showing current activity, but only one active maintainer contributed during that period.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but all four references are unpinned and the high-confidence unpinned-tools finding weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/routing Version ^6.4 || ^7.4 || ^8.0 | — | — |
myclabs/deep-copy Version ^1.10 | — | — |
symfony/validator Version ^6.4 || ^7.4 || ^8.0 | — | — |
phpstan/phpdoc-parser Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.