This release appears suitable to depend on from a supply-chain health perspective: it is actively released, not deprecated or archived, has a matching repository, includes substantial documentation, tests, changelog, licensing, CI tooling, and read-only workflow permissions. The main risks are that the project is young and remains below 1.0, all 22 recent commits come from one contributor, and the repository has very little community adoption or issue activity. These concerns suggest some maintainer and continuity risk, but current activity and repository hygiene provide meaningful compensation.
78%
Total Score
70
50
89
90
The package has 12 runtime dependencies, including several Symfony and OpenAPI components. This is a meaningful integration surface and some upgrade exposure, but the dependencies are coherent with the bundle's stated functionality.
Only one registry account has publishing access. Because the repository is user-owned rather than organization-owned, this represents a genuine publishing continuity risk, although repository activity shows that the maintainer is currently active.
The repository is owned by a user account rather than an organization, so there is no demonstrated organizational handoff or backing to compensate for the concentrated maintainer base.
One contributor made 100% of the 22 commits in the last three months. With a user-owned project and no second active contributor shown, maintainer loss would materially threaten continuity.
The repository has only 1 star, 0 forks, and 0 watchers, so external adoption and independent scrutiny appear limited. Low popularity is supporting caution rather than a standalone failure because active maintenance is present.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
symfony/messenger Version ^7.3 || ^8.0 | — | — |
symfony/validator Version ^7.3 || ^8.0 | — | — |
symfony/serializer Version ^7.3 || ^8.0 | — | — |
nelmio/api-doc-bundle Version ^5.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.