It has an MIT license, tests, a matching repository, and organization backing. However, releases stopped about 17 months ago, commits stopped in the last 3 months, and all workflow actions are unpinned.
38%
Total Score
67
75
100
The package is flagged as borrowing the identity of sensiolabs/security-checker, which has far more downloads and stable releases; this is strong evidence consumers may have intended the lookalike package.
The project has existed since 2014 with 19 releases, but it has had no releases in the last 12 months and the latest release was about 17 months ago, increasing abandonment risk.
The repository had zero commits and zero active maintainers in the last 3 months, which indicates currently inactive development.
There were no new or closed issues or pull requests in the last month, consistent with the recent lack of commit activity.
Both workflows were analyzed successfully and expose no dangerous triggers or audit findings, but all 8 action references are unpinned, leaving build inputs less reproducible.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
jms/serializer Version ^3.29 | — | — |
symfony/console Version ^5.4|^6.4|^7.0 | — | — |
symfony/http-client Version ^5.4|^6.4|^7.0 | — | — |
doctrine/annotations Version ^1.14|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.