The package has solid tests, documentation, licensing, and organization backing. Its maintenance record is still too short to establish dependable long-term support, and the repository has no security policy or scanning tooling.
62%
Total Score
75
100
81
75
This is a young package, about five months old, with only one release and no established release cadence. That limits evidence of maturity, though the package is not abandoned based on this signal alone.
There were no commits and no active maintainers during the last three months. For a package this new, that is a meaningful warning about maintenance momentum, despite the recent repository push recorded elsewhere.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package's tests, README, and organization backing provide some compensating project structure.
The current v0.1.0 release is not a stable major version, so its API and behavior may change substantially. It is not marked as a prerelease, which provides a small compensating signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
solidframe/core Version ^0.1 | — | — |
symfony/console Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.