The MIT license, README, release notes, and substantial test suite improve transparency. Unpinned workflow actions and no security policy leave smaller hygiene gaps.
42%
Total Score
50
75
50
The package has only four releases, with none in the last 12 months; its latest registry release was in October 2020. This is strong evidence that maintenance has stopped.
There were no commits or active maintainers in the past three months, and the repository was last pushed in December 2020. This materially increases abandonment risk.
No issues or pull requests were opened or closed in the past month, while three issues remain open. Combined with the stale commit history, this suggests inactive maintenance.
The repository has no security policy. This is a modest transparency and vulnerability-reporting gap, though it does not by itself show the package is unsafe to depend on.
Version 0.1.3 is not a prerelease, but it remains below 1.0, so the package offers less maturity and compatibility assurance than a stable-major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.1 | — | — |
php-di/php-di Version ^6.2 | — | — |
symfony/finder Version ^5.1 | — | — |
ralouphie/mimey Version ^2.1 | — | — |
symfony/console Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.