Tests are present, and the repository is not archived. The small project has one active contributor and no security policy, so future support remains uncertain.
55%
Total Score
67
75
75
Tests are included and the project uses GitHub releases, which support maturity. However, the four-character README containing only “WIP” gives consumers almost no integration guidance for this library.
Only two releases exist, with the latest published over four years ago and none in the last 12 months. A repository push in August 2026 provides some compensating activity, but the release gap remains a maintenance concern.
All recent commits come from one contributor. Organization backing offers some handoff capacity, but no second recently active contributor is visible to reduce continuity risk.
The repository recorded only one commit in the last three months from one active maintainer. The recent push shows the project is not entirely dormant, but activity is still very thin.
The repository name matches the package, reducing the risk of an unrelated source repository. It does not mention the package in its README, leaving consumer-facing ownership and purpose less clearly documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^5.4|^6.0 | — | — |
symfony/yaml Version ^5.4|^6.0 | — | — |
symfony/validator Version ^5.4|^6.0 | — | — |
doctrine/annotations Version ^1.2 | — | — |
doctrine/collections Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.