The project has a clear license, release notes, tests, and organization backing. Recent release and commit activity has slowed, while all nine workflow actions are unpinned and no security scanning or policy is present.
68%
Total Score
67
100
88
67
The package has existed since 2016 with 30 releases and a median interval of about 32 days, but it had no releases in the last 12 months, indicating a meaningful slowdown.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of current maintenance capacity.
There were five open issues and no issue or pull-request activity in the last month, a modest sign of limited current project activity.
The project uses Composer, Make, and Box for builds, but no security-scanning tools were detected, leaving a security-hygiene gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rokka/client Version ^1.9.0 | — | — |
symfony/yaml Version ^5.2 || ^6.0 || ^7.0 | — | — |
symfony/config Version ^5.2 || ^6.0 || ^7.0 | — | — |
symfony/finder Version ^5.2 || ^6.0 || ^7.0 | — | — |
symfony/console Version ^5.2 || ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.