Tests, a changelog, and recent releases provide useful continuity. The organization behind the repository helps, but the project has little visible community activity and no published security policy.
68%
Total Score
63
100
86
75
Only one registry account has publish access, which is a publishing concentration risk, although this is partly offset by the organization-owned source repository.
The source repository has tests and a changelog, which improve maintainability and release transparency. The package artifact lacks a README, a minor integration gap for a library.
All 2 recent commits came from one contributor. Organization backing provides some handoff capacity, but no second active contributor is evidenced.
The repository received 2 commits in the last 3 months, demonstrating recent activity but at a low pace.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
slick/json-api Version ^1.2 | — | — |
symfony/framework-bundle Version ^7|^8 | — | — |
symfony/psr-http-message-bridge Version ^7|^8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.