The package includes release notes, repository tests, and a clear MIT license. Its small contributor base and one unpinned workflow action merit routine caution, but active project backing supports continued maintenance.
82%
Total Score
83
100
81
83
Two contributors are active, but one accounts for five of six recent commits, so maintenance is concentrated. Organization backing partly offsets the handoff risk.
The repository has only two stars and one fork, indicating limited adoption evidence. Popularity is supporting evidence, so this is a minor concern rather than a health verdict.
Composer build tooling is present, but no security-scanning tools were detected. The absence is a modest transparency gap, not evidence of unsafe code.
The release is not on a stable major version, but it is not a prerelease and recent releases have no prerelease share, so this is only a mild maturity consideration.
The single workflow has a pull_request_target trigger but no untrusted checkout or script-injection sink, and the audit completed cleanly. Its one action is unpinned, which is a minor supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^7.3|^8.0 | — | — |
symfony/ai-store Version ^0.14 | — | — |
symfony/ai-platform Version ^0.14 | — | — |
oskarstark/enum-helper Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.