Healthy and reasonable to adopt. It has a maintained, unarchived organizational repository, recent releases, tests, documentation, and a clean package match; the main caveats are its pre-1.0 version and concentrated contributor activity, with no repository security policy.
84%
Total Score
88
100
83
80
Two contributors were active, but one produced about 82% of recent commits. The organization backing provides some handoff capacity, yet maintenance remains concentrated.
The repository has only 2 stars and 1 fork, providing little external adoption evidence; this is a supporting weakness, not a health verdict, because maintenance activity is present.
The repository uses Composer build tooling, but no security-scanning tools were detected. The build setup is present; the missing scanning is a transparency and assurance gap.
No SECURITY.md or other repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
The only workflow lacks top-level GitHub Actions permissions. Although no write permissions were declared, explicitly restricting permissions would provide clearer workflow hardening.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^4.0.0 || ^5.3 || ^6.0 || ^7.0 | — | — |
symfony/console Version ^4.0.0 || ^5.3 || ^6.0 || ^7.0 | — | — |
symfony/process Version ^4.0.0 || ^5.4 || ^6.0 || ^7.0 | — | — |
doctrine/inflector Version ~1.4.2 || ~2.0.0 | — | — |
symfony/property-access Version ^4.0.0 || ^5.4 || ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.