The repository has tests, a clear MIT license, and no install-time scripts. Its small audience and inactive recent commit history reduce confidence in ongoing maintenance, while all eight workflow actions are unpinned.
67%
Total Score
75
100
83
67
The package is over four years old but has only four releases, with a median interval of about 559 days. A release within the last year provides some evidence of continued maintenance, so this is a modest concern rather than a severe risk.
There were no commits and no active maintainers in the three months before collection. The recent release is compensating evidence, but the lack of ongoing repository activity still lowers maintenance confidence.
The repository has only 2 stars and no forks, indicating a very small user base. Popularity is supporting evidence rather than a verdict, so this adds only a limited maintenance concern.
The repository has no published security policy, which reduces transparency for reporting and handling vulnerabilities. This is a documentation gap, not evidence that the package is unsafe.
Version 0.5.0 is not a stable-major release, which leaves more room for compatibility changes. It is not marked as a prerelease, partially offsetting that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.