Documentation, tests, licensing, and a security policy are in place. The organization provides some continuity, but evidence of ongoing maintenance remains limited.
68%
Total Score
67
100
88
83
The package is young at 99 days, with two releases and a roughly four-day median interval; this shows an initial release effort but not a long maintenance record.
All recent commit activity comes from one contributor. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
Only one commit was recorded in the last three months and one maintainer was active, so recent maintenance evidence is thin for a package released about 99 days ago.
Composer build tooling is present, but no security-scanning tool was detected; the repository's separate security policy partly improves transparency but does not replace scanning.
Both workflows were analyzed without audit findings or untrusted-input sinks, and one workflow uses read-only permissions. However, all four action references are unpinned and one workflow has top-level write permissions, creating a mild reproducibility and token-scope concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^8.0 | — | — |
sympress/kernel Version dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.