The package includes a substantial README, tests, a matching repository, and no install-time scripts. Its small audience and absent security scanning leave less independent assurance.
68%
Total Score
50
100
81
83
The repository is owned by an individual account, so the two registry maintainers do not represent broad organizational backing.
The latest registry release was over two years ago and there were no releases in the last 12 months, which raises maintenance concerns. A recent repository push provides some compensating evidence but does not show ongoing published releases.
There were no commits and no active maintainers in the last three months, weakening evidence of current development. The repository's recent push partly offsets this but does not establish sustained activity.
The repository has only 2 stars and no forks, so there is little external adoption evidence. Popularity is supporting evidence rather than a decisive health measure.
The project uses Composer and Robo for builds, but no security scanning tools were detected, leaving a modest assurance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^4.4 || ^5.0 || ^6.0 || ^7.0 | — | — |
symfony/filesystem Version ^4.4 || ^5.4 || ^6.0 || ^7.0 | — | — |
sweetchuck/composer-suite-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.