It includes tests, Composer tooling, and security scanning, with no deprecation or archive status. The pre-1.0 version and install hooks add some adoption and supply-chain friction.
62%
Total Score
75
88
50
The package runs post-install and post-update Composer scripts, which add execution during dependency operations and therefore modest supply-chain exposure. No other provided signal shows those scripts are unsafe.
The package has only 4 releases since March 2021 and none in the last 12 months; the latest release was about 20 months ago. This indicates a slow release cadence, though it does not by itself prove abandonment.
There were 0 commits and 0 active maintainers in the last 3 months, weakening evidence of active maintenance. The recent repository push provides some counterevidence but does not establish ongoing development.
The repository has no security policy, leaving disclosure and response expectations undocumented. This is a transparency gap, not evidence that the package is unsafe.
Version 0.4.0 is not a stable major release, so its API and behavior may still change before 1.0. It is not marked as a prerelease, which partly reduces the concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^2.0 | — | — |
symfony/yaml Version * | — | — |
solido/solido Version ^0.4 | — | — |
kcs/serializer Version ^4.5 | — | — |
solido/symfony Version ^0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.