Documentation and test coverage make integration clearer, while the dependency set is modest. The CI workflow leaves both actions unpinned and no security policy is published; reassess after sustained maintenance.
65%
Total Score
50
100
81
75
The registry namespace and repository owner match, but the owner is an individual account rather than an organization; this offers limited evidence of broader project backing.
All six releases occurred on the package's first observed day, so the project has no demonstrated release track record or long-term maintenance history yet.
The repository records zero commits and zero active maintainers over the last three months. Because the package is newly published, this may reflect its age, but it leaves maintenance capacity unproven.
Composer and Make are used for project tooling, but no security-scanning tool was detected, leaving a modest repository hygiene gap.
The repository has no published security policy, so vulnerability reporting and response expectations are less transparent for adopters.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.4 || ^8.1 | — | — |
symfony/http-kernel Version ^6.4 || ^7.4 || ^8.1 | — | — |
sigbits/php-amqp-client Version ^1.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.4 || ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.