The focused seven-file artifact has no install-time scripts, and the registry is not withdrawing it. Two active contributors provide useful continuity, though no security policy or scanning is present.
76%
Total Score
100
100
81
75
The package is only 55 days old, with all three releases arriving within roughly 13 minutes. That shows initial activity but leaves too little history to establish durable maintenance.
Composer build tooling is present, but no security-scanning tool was detected. The missing scan is a transparency and maintenance gap rather than evidence of a specific defect.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This lowers transparency but is not independently severe for a small bundle.
Version 0.3.0 is a stable release rather than a prerelease, but the 0.x major version signals that breaking changes remain possible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
shyim/sasso-ffi Version ^0.1 | — | — |
shopware/storefront Version ~6.6.0 || ~6.7.0 || ~6.8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.