The repository includes tests and a usable README, while the MIT declaration and lack of install scripts reduce adoption friction. The project remains early-stage, with one release in about five months and no security policy, so pinning this version deserves caution.
62%
Total Score
79
75
This package has made only one release in about five months, so its maintenance cadence and long-term support are not yet established.
The project uses Make and Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting expectations and response processes unclear.
Version 0.1.0 is an early, non-stable-major release, which indicates that APIs and behavior may still change substantially.
No GitHub Actions workflows were present, so this audit found no workflow triggers, token permissions, or action-pinning problems; it also provides no evidence of automated release or security checks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^8.0 | — | — |
shrikeh/cqrs Version ^0.4.0 | — | — |
symfony/messenger Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.