The package includes tests, a changelog, release notes, clear usage documentation, and no install-time scripts. Its only publisher is one person, recent commit activity is absent, and the workflows use unpinned actions with one high-confidence package-installation warning.
68%
Total Score
50
89
75
Only one account has registry publish access. That is a limited publishing base, and the user-owned project provides no organizational backing to offset the resulting continuity risk.
The registry namespace and repository owner match, but both identify a user-owned project rather than an organization. This supports ownership consistency without providing organizational continuity.
The repository recorded zero commits and zero active maintainers during the last three months. This indicates maintenance has gone quiet after the latest release and raises abandonment risk.
There are no open issues or pull requests, which is operationally tidy, but there was also no issue or pull-request activity in the measured month; the lack of recent commits remains the stronger maintenance signal.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/stream Version ^1.0.0 | — | — |
symfony/yaml Version ^6.0 | — | — |
symfony/finder Version ^6.0 | — | — |
symfony/console Version ^6.0 | — | — |
symfony/process Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.