Usable with caveats: the package is actively released, has tests, documentation, and a matching source repository, but no commits were recorded in the last three months. Its Composer install and update hooks also change Git hook configuration, so review that behavior before adopting it.
70%
Total Score
67
100
89
75
The package runs post-install and post-update Composer scripts, which is central to deploying its Git hooks but gives installation-time code execution and repository configuration changes extra importance.
The registry namespace and repository owner match, but the repository is user-owned rather than organization-backed, so the project has limited visible institutional support.
No commits and no active maintainers were recorded during the last three months, a meaningful maintenance concern, although a recent registry release and recent repository push provide some compensating evidence.
The repository has only 2 stars and no forks, indicating a small user base; this is supporting caution but not decisive because the project shows documentation, tests, and recent release activity.
The repository uses Composer and Robo build tooling, but no security scanning tools were detected; this is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/filesystem Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.