Organization backing and a matching, documented repository support continuity, while the small project has no security policy and recent work comes from one contributor. Its focused artifact and clean install and workflow profile reduce the practical concern.
79%
Total Score
67
100
83
One contributor made 100% of the recent commits, creating concentrated maintenance dependence; organization backing partly offsets the risk but does not remove it.
Two commits were made in the last 3 months by one active maintainer. Recent work exists, but its low volume limits evidence of sustained maintenance capacity.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is a moderate concern rather than evidence that the package is unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version ^6.2 || ^7.0 || ^8.0 | — | — |
rekalogika/file-contracts Version ^2.4.4 | — | — |
rekalogika/file-symfony-bridge Version ^2.4.4 | — | — |
rekalogika/temporary-url-bundle Version ^1.7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.