The package includes a README, tests, a stable version, and a declared license. Recent repository work is sparse and concentrated in one contributor, so future fixes may depend on a single maintainer.
60%
Total Score
50
88
50
The repository is owned by an individual account rather than an organization. That does not make the package unhealthy, but it offers no organizational redundancy to offset the concentrated recent activity.
The latest registry release was about two years ago, with no releases in the last 12 months. This suggests slowing maintenance despite a history of six releases since 2022.
All recent commits came from one contributor, leaving maintenance highly concentrated. The repository is user-owned rather than organization-owned, so no provided backing signal compensates for that concentration.
Only one commit was recorded in the last three months, showing limited recent development activity. This reinforces the release-history concern, although it does show the repository is not entirely inactive.
Composer and Robo provide build tooling, but no security-scanning tools were detected. This is a modest hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
symfony/console Version ^5.1 || ^6.0 || ^7.0 | — | — |
symfony/filesystem Version ^5.4 || ^6.0 || ^7.0 | — | — |
symfony/dependency-injection Version ^5.3 || ^6.0 || ^7.0 | — | — |
sweetchuck/composer-suite-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.